Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 614666 (CVE-2017-4902, CVE-2017-4903, CVE-2017-4904, CVE-2017-4905, VMSA-2017-0006) - app-emulation/vmware-workstation: multiple vulnerabilities
Summary: app-emulation/vmware-workstation: multiple vulnerabilities
Status: RESOLVED OBSOLETE
Alias: CVE-2017-4902, CVE-2017-4903, CVE-2017-4904, CVE-2017-4905, VMSA-2017-0006
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal trivial (vote)
Assignee: Gentoo Security
URL: https://www.vmware.com/security/advis...
Whiteboard: ~1 [ebuild/cve]
Keywords: PMASKED
Depends on:
Blocks:
 
Reported: 2017-04-04 17:24 UTC by Manfred Knick
Modified: 2017-11-25 15:31 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Manfred Knick 2017-04-04 17:24:24 UTC
Assignee: @ Gentoo Security
CC:       @ Gentoo VMWare Bug Squashers
CC:       @ Thomas Deutschmann <whissi@gentoo.org>

Upgrade to version 12.5.5 necessary; all former versions affected; no workaround.

Pre-decessor: Bug 612804  [ https://bugs.gentoo.org/show_bug.cgi?id=612804 ]

Same procedure ... 
Please, don't lose sight of [ https://bugs.gentoo.org/show_bug.cgi?id=612804#c11 ]

Ebuilds needed:
- app-emulation/vmware-modules-308.5.5.ebuild
- app-emulation/vmware-workstation-12.5.5.5234757.ebuild

Download:

[ https://my.vmware.com/en/web/vmware/free#desktop_end_user_computing/vmware_workstation_player/12_0 ]

Release-Notes, including descriptions:

[ http://pubs.vmware.com/Release_Notes/en/workstation/12pro/workstation-1255-release-notes.html ] :

<cite>

What's New

This release of VMware Workstation Pro is a free upgrade for all VMware Workstation 12 Pro users. It contains bug fixes and security updates.
Important Fixes

This release of VMware Workstation Pro addresses the following issues:

    VMware Workstation Pro has a heap buffer overflow and uninitialized stack memory usage in SVGA. These issues might allow a guest virtual machine to execute code on the host.
    The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2017-4902 (heap issue) and CVE-2017-4903 (stack issue) to these issues.
    The VMware Workstation Pro XHCI driver has uninitialized memory usage. This issue might allow a guest virtual machine to execute code on the host.
    The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4904 to this issue.
    VMware Workstation Pro has uninitialized memory usage. This issue might lead to an information leak.
    The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4905 to this issue.

</cite>


Reproducible: Always
Comment 1 Thomas Deutschmann (RETIRED) gentoo-dev 2017-04-04 18:06:56 UTC
Thanks for the report. Marking as trivial because no stable ebuild affected.

VMSA-2017-0006 is about Pwn2Own 2017 reported VM escape.
Comment 2 Manfred Knick 2017-04-04 18:25:18 UTC
(In reply to Thomas Deutschmann from comment #1)

> Thanks for the report.

My pleasure.

Quick test (Upgrade VMware Tools inside a Win7 VM) succeeded.
Comment 3 Manfred Knick 2017-04-04 18:43:15 UTC
(In reply to Manfred Knick from comment #0)

> Please, don't lose sight of [https://bugs.gentoo.org/show_bug.cgi?id=612804#c11]

Also [https://bugs.gentoo.org/show_bug.cgi?id=612804#c2] still holds true.

@ Fabio:

... app-emulation/vmware-tools/vmware-tools-9.9.5.3848939.ebuild

seems still appropriate again?

Thanks.
Comment 4 Thomas Deutschmann (RETIRED) gentoo-dev 2017-06-17 10:01:29 UTC
To address bug 621910 we had to PMASK currently unmaintained VMware packages within the Gentoo repository.
Comment 5 Thomas Deutschmann (RETIRED) gentoo-dev 2017-11-25 15:31:06 UTC
VMware was removed from the Gentoo repository [1]. Closing as obsolete (package was never stable, i.e. no removal GLSA required).



[1] https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=a2d54401ad16fe676b80bb5618a569ebe02636d5