Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 516044 - <app-emulation/vmware-player-6.0.3.1895310: OpenSSL Vulnerability (CVE-2014-{0198,0224,3470,5298})
Summary: <app-emulation/vmware-player-6.0.3.1895310: OpenSSL Vulnerability (CVE-2014-{...
Status: RESOLVED FIXED
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High trivial with 1 vote (vote)
Assignee: Gentoo Security
URL: https://www.vmware.com/support/player...
Whiteboard: ~1 [noglsa]
Keywords:
: 524610 (view as bug list)
Depends on:
Blocks:
 
Reported: 2014-07-02 07:59 UTC by Frank Krömmelbein
Modified: 2016-03-20 23:03 UTC (History)
6 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Frank Krömmelbein 2014-07-02 07:59:08 UTC
Security Updates for all these VMWare products for the well known OpenSSL security issues.

... been updated to the OPENSSL library version openssl-0.9.8za where necessary to address CVE-2014-0224 , CVE-2014-0198, CVE-2010-5298, and CVE-2014-3470.


Release notes vmware-player:
https://www.vmware.com/support/player60/doc/player-603-release-notes.html#knownissues



Reproducible: Always
Comment 1 Greg Turner 2014-07-02 10:25:36 UTC
Workstation 10.0.3 is now in my overlay:  https://github.com/gmt/gmt-vmware-overlay/.  Enjoy!
Comment 2 Timo Rothenpieler 2014-07-23 17:06:02 UTC
Why hasn't this quite important security update hit portage after nearly a month?
Comment 3 René 2014-08-22 13:04:30 UTC
for vmware-workstation simply copying the 10.0.2 ebuild and the vmware-modules 279.2 ebuild worked for me
Comment 4 Frank Krömmelbein 2014-09-06 15:12:01 UTC
I can not understand that these ebuilds are still not been updated. 
The rename of the available ebuilds has worked for me.

I do not know if my procedure now is ok. 
But since it also comes to a safety problem and now after more than 2 months nothing has happened, I have now set security@gentoo.org on the CC list.

Please rev bump the affected Ebuilds.
Comment 5 Nikos Chantziaras 2014-10-14 10:47:10 UTC
For Workstation, this is a non-issue on Gentoo. This update is not needed, because the system openssl library is used. The bundled openssl version is deleted during the install phase.

However, this is only true for Workstation. The Player's openssl lib is NOT unbundled:

        # exclude OpenSSL from unbundling until the AES-NI patch gets into the tree
        # see http://forums.gentoo.org/viewtopic-t-835867.html
Comment 6 Yury German Gentoo Infrastructure gentoo-dev 2014-10-15 01:56:47 UTC
Changing this to a security bug.

This is related to the SSL issues as were assigned an A1 for openssl.
Comment 7 Yury German Gentoo Infrastructure gentoo-dev 2014-10-15 02:11:19 UTC
*** Bug 524610 has been marked as a duplicate of this bug. ***
Comment 8 Andreas K. Hüttel archtester gentoo-dev 2014-10-16 22:01:27 UTC
All bumped. Mostly untested so far but should be unproblematic.

app-emulation/vmware-player-6.0.3.1895310
app-emulation/vmware-modules-279.3
app-emulation/vmware-workstation-10.0.3.1895310
Comment 9 Andreas K. Hüttel archtester gentoo-dev 2015-09-19 18:49:27 UTC
All affected versions of vmware-player removed
All affected versions of vmware-workstation package.masked (keeping 9 around for users who only have a license for that)

Security please do your thing
Comment 10 Andreas K. Hüttel archtester gentoo-dev 2016-03-20 18:38:09 UTC
(In reply to Andreas K. Hüttel from comment #9)
> All affected versions of vmware-player removed
> All affected versions of vmware-workstation package.masked (keeping 9 around
> for users who only have a license for that)
> 
> Security please do your thing

@ security: ping
Comment 11 Aaron Bauman (RETIRED) gentoo-dev 2016-03-20 23:03:23 UTC
(In reply to Andreas K. Hüttel from comment #10)
> (In reply to Andreas K. Hüttel from comment #9)
> > All affected versions of vmware-player removed
> > All affected versions of vmware-workstation package.masked (keeping 9 around
> > for users who only have a license for that)
> > 
> > Security please do your thing
> 
> @ security: ping

Andreas, no GLSA is required here due to the package never having been stabilized.  I apologize for the delay.