CVE-2010-1138 Information

Description

The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600 VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows VMware Player 3.0 before 3.0.1 build 227600 VMware Player 2.5.x before 2.5.4 build 246459 on Windows VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459 VMware Server 2.x and VMware Fusion 3.0 before 3.0.1 build 232708 and 2.x before 2.0.7 build 246742 allows remote attackers to obtain sensitive information from memory on the host OS by examining received network packets related to interaction between the guest OS and the host vmware-vmx process.

Reference

http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html http://lists.vmware.com/pipermail/security-announce/2010/000090.html http://osvdb.org/63607 http://secunia.com/advisories/39203 http://secunia.com/advisories/39206 http://secunia.com/advisories/39215 http://security.gentoo.org/glsa/glsa-201209-25.xml http://www.securityfocus.com/bid/39395 http://www.securitytracker.com/id?1023836 http://www.vmware.com/security/advisories/VMSA-2010-0007.html

Share on: