Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 236167 (CVE-2007-5269) - app-emulation/vmware-* multiple vulnerabilities (CVE-2007-{5269,5503}, CVE-2008-{1447,1806,1807,1808,2101})
Summary: app-emulation/vmware-* multiple vulnerabilities (CVE-2007-{5269,5503}, CVE-20...
Status: RESOLVED FIXED
Alias: CVE-2007-5269
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High major (vote)
Assignee: Gentoo Security
URL:
Whiteboard: B1 [glsa]
Keywords:
: 236693 236805 237558 237631 239085 CVE-2008-4279 (view as bug list)
Depends on:
Blocks:
 
Reported: 2008-08-30 06:21 UTC by Paweł Hajdan, Jr. (RETIRED)
Modified: 2012-09-29 16:26 UTC (History)
7 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments
vmsa-2008-14-full.txt (vmsa-2008-14-full.txt,25.47 KB, text/plain)
2008-08-30 06:22 UTC, Paweł Hajdan, Jr. (RETIRED)
no flags Details
VMware Server 1.0.7 ebuild (vmware-server-1.0.7.108231.ebuild,2.94 KB, text/plain)
2008-09-14 13:29 UTC, Brian Knoll
no flags Details

Note You need to log in before you can comment on or make changes to this bug.
Description Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2008-08-30 06:21:11 UTC
From VMSA-2008-0014

1. Summary

     Updates to VMware Workstation, VMware Player, VMware ACE, VMware
     Server, VMware ESX address information disclosure, privilege
     escalation and other security issues.

2. Relevant releases

     VMware Workstation 6.0.4 and earlier,
     VMware Workstation 5.5.7 and earlier,
     VMware Player 2.0.4 and earlier,
     VMware Player 1.0.7 and earlier,
     VMware ACE 2.0.4 and earlier,
     VMware ACE 1.0.6 and earlier,
     VMware Server 1.0.6 and earlier,

Will attach the full advisory in a moment. It was sent to full-disclosure, and has not been published on webpage yet.
Comment 1 Paweł Hajdan, Jr. (RETIRED) gentoo-dev 2008-08-30 06:22:28 UTC
Created attachment 164107 [details]
vmsa-2008-14-full.txt
Comment 2 Robert Buchholz (RETIRED) gentoo-dev 2008-08-30 12:17:38 UTC
Linux vulnerabilities are the following:
 d. Update to Freetype

     FreeType 2.3.6 resolves an integer overflow vulnerability and other
     vulnerabilities that can allow malicious users to run arbitrary code
     or might cause a denial-of-service after reading a maliciously
     crafted file. This release updates FreeType to 2.3.7.

     The Common Vulnerabilities and Exposures Project (cve.mitre.com)
     has assigned the names CVE-2008-1806, CVE-2008-1807, and
     CVE-2008-1808 to the issues resolved in Freetype 2.3.6.


This only affects ~arch:
 e. Update to Cairo

     Cairo 1.4.12 resolves an integer overflow vulnerability that can
     allow malicious users to run arbitrary code or might cause a
     denial-of-service after reading a maliciously crafted PNG file.
     This release updates Cairo to 1.4.14.

     The Common Vulnerabilities and Exposures (cve.mitre.com) has
     assigned the name CVE-2007-5503 to this issue.

Please also note the following (quote):
     NOTE: Hosted products VMware Workstation 5.x, VMware Player 1.x,
           and VMware ACE 1.x will reach end of general support
           2008-11-09. Customers should plan to upgrade to the latest
           version of their respective products.

We should proceed the 6.x versions for stable soon.
Comment 3 Mike Auty (RETIRED) gentoo-dev 2008-09-04 18:21:56 UTC
I'm not going to be able to get to these this weekend.  I'm busy and also having connection difficulties.  I expect the bumps for vmware-server and player to be relatively easy if someone wants to have a go at them.  Please ensure to test with a 2.6.25 kernel if you're going to give it a go.  Hopefully I'll be able to get to these towards the tail end of next week...
Comment 4 Robert Buchholz (RETIRED) gentoo-dev 2008-09-04 18:37:00 UTC
*** Bug 236693 has been marked as a duplicate of this bug. ***
Comment 5 Carsten Lohrke (RETIRED) gentoo-dev 2008-09-05 19:51:49 UTC
*** Bug 236805 has been marked as a duplicate of this bug. ***
Comment 6 Carsten Lohrke (RETIRED) gentoo-dev 2008-09-14 00:19:16 UTC
*** Bug 237558 has been marked as a duplicate of this bug. ***
Comment 7 Mike Auty (RETIRED) gentoo-dev 2008-09-14 13:22:10 UTC
*** Bug 237631 has been marked as a duplicate of this bug. ***
Comment 8 Brian Knoll 2008-09-14 13:29:55 UTC
Created attachment 165397 [details]
VMware Server 1.0.7 ebuild

I have tested this on amd64 but not on x86.  It really should have additional testing on both amd64 and on x86.
Comment 9 Robert Buchholz (RETIRED) gentoo-dev 2008-09-14 13:56:02 UTC
Mike, what's the progress with the ebuilds?
Comment 10 Mike Auty (RETIRED) gentoo-dev 2008-09-14 14:30:27 UTC
Still working on them.  I've set aside a couple of hours to get 2.6.25 back on my development machine so I can get all these rebuilt, tested and into the overlay.  Hopefully by this evening is the best I can offer...
Comment 11 Mike Auty (RETIRED) gentoo-dev 2008-09-14 22:51:19 UTC
Ok, the following bumps are now in the overlay for testing:

vmware-player-1.0.8.108000
vmware-player-2.0.5.109488
vmware-server-1.0.7.108231
vmware-server-console-1.0.7.108231
vmware-workstation-5.5.8.108000
vmware-workstation-6.0.5.109488
vmware-modules-1.0.0.22

Please test them out, particularly vmware-workstation-5.5.8 (I've only tested the corresponding vmware-player, version 1.0.8.108000).  If everything goes ok, I'll shuffle them over to the main tree in the coming week...
Comment 12 Stefan Behte (RETIRED) gentoo-dev Security 2008-09-22 13:59:39 UTC
Are there any issues left?!
Comment 13 Mike Auty (RETIRED) gentoo-dev 2008-09-30 10:39:08 UTC
*** Bug 239085 has been marked as a duplicate of this bug. ***
Comment 14 Mike Auty (RETIRED) gentoo-dev 2008-09-30 20:40:44 UTC
Ok, versions now in the main tree are:

vmware-workstation-5.5.8.108000
vmware-workstation-6.0.5.109488
vmware-player-1.0.8.108000
vmware-player-2.0.5.109488
vmware-server-1.0.7.108231
vmware-server-console-1.0.7.108231
Comment 15 Jonathan Heaney 2008-10-01 00:08:53 UTC
Vmware-workstation 6.0.5 is now build 118166, 109488 is no longer available.  It appears to be a 'bundle', whatever that is, but at 381 MB I've not downloaded it yet, and will wait to see what happens in portage.
Comment 16 Mike Auty (RETIRED) gentoo-dev 2008-10-01 00:11:58 UTC
Jonathan, vmware-workstation 6.0.5 is at build 109488.  You're talking about vmware-workstation 6.5.0, which is indeed at build 118166, but that's not what this bug is about.  If you're interested in vmware-workstation-6.5, please see bug 232230.  Thanks...  5:)
Comment 17 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-19 11:44:03 UTC
*** Bug 241150 has been marked as a duplicate of this bug. ***
Comment 18 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-19 11:53:23 UTC
CVE-2008-4279 from 241150 will be handled here, too (same versions have to go stable).

Mike, are these versions tested enough and ready for going into stable?
I'd really like to have a version in tree that resolves those (severe) security issues!
Comment 19 Mike Auty (RETIRED) gentoo-dev 2008-10-19 12:05:13 UTC
Craig, comment 14 shows these ebuilds have been in the tree since the 30th of September.  Stabilizing is up to the appropriate arch/security teams.  
Comment 20 Daniele C. 2008-10-19 13:24:37 UTC
vmware-player-2.0.5.109488 fixes bug 233784, I confirm it is stable for x86
Comment 21 Robert Buchholz (RETIRED) gentoo-dev 2008-10-19 15:24:43 UTC
Sorry for the delay in adding arches.

Arches, please test and mark stable:
=app-emulation/vmware-workstation-5.5.8.108000
=app-emulation/vmware-player-1.0.8.108000
=app-emulation/vmware-server-1.0.7.108231
=app-emulation/vmware-server-console-1.0.7.108231
Target keywords : "amd64 x86"

Comment 22 Stefan Behte (RETIRED) gentoo-dev Security 2008-10-19 17:51:19 UTC
(In reply to comment #19)
> Craig, comment 14 shows these ebuilds have been in the tree since the 30th of
> September.  Stabilizing is up to the appropriate arch/security teams.  
> 

I read that, but wasn't sure if all issues (usual VMWare Kernel version/module problems) were fixed, that's why I asked you as the maintainer first and did not add arches directly.
Comment 23 Mike Auty (RETIRED) gentoo-dev 2008-10-19 17:54:07 UTC
Hiya Craig, yep those issues still exist.  The older modules don't work with 2.6.26+ and the newer ones don't work with 2.6.27+.  Luckily 2.6.25 is still the stable gentoo-sources.  I'm currently trying to get the latest versions of vmware working...
Comment 24 Eric Paynter 2008-11-30 17:43:27 UTC
Stable gentoo sources is now 2.6.26-r3. Current stable vmware modules will no longer install against stable gentoo sources.
Comment 25 Mike Auty (RETIRED) gentoo-dev 2009-01-10 13:14:04 UTC
Ok, vwmare-modules-1.0.0.15-r2 just hit the tree, but this bug has been superceded by bug 245941.  I'm not sure whether this just gets closed, or what...
Comment 26 Markus Meier gentoo-dev 2009-01-11 22:09:12 UTC
amd64/x86 stable, all arches done.
Comment 27 Andreas K. Hüttel archtester gentoo-dev 2010-07-14 21:07:43 UTC
@security: "all arches done" was january 2009. can we close this one too?
Comment 28 Stefan Behte (RETIRED) gentoo-dev Security 2010-08-01 13:42:48 UTC
glsa request filed.
Comment 29 GLSAMaker/CVETool Bot gentoo-dev 2012-09-29 16:26:17 UTC
This issue was resolved and addressed in
 GLSA 201209-25 at http://security.gentoo.org/glsa/glsa-201209-25.xml
by GLSA coordinator Sean Amoss (ackle).