|
Vulnerability Assessment & Network Security Forums |
|||||||||
If through a vulnerability assessment, a network security issue is detected for the vulnerability below, applying the appropriate security patches in a timely matter is very important. If you have detected that your system has already been compromised, following CERT's Network Security recovery document will assist with recommended steps for system recovery. Home >> Browse Vulnerability Assessment Database >> Gentoo Local Security Checks >> [GLSA-200502-18] VMware Workstation: Untrusted library search path Vulnerability Assessment Details
|
[GLSA-200502-18] VMware Workstation: Untrusted library search path |
||
VMware Workstation: Untrusted library search path Detailed Explanation for this Vulnerability Assessment The remote host is affected by the vulnerability described in GLSA-200502-18 (VMware Workstation: Untrusted library search path) Tavis Ormandy of the Gentoo Linux Security Audit Team has discovered that VMware Workstation searches for gdk-pixbuf loadable modules in an untrusted, world-writable directory. Impact A local attacker could create a malicious shared object that would be loaded by VMware, resulting in the execution of arbitrary code with the rights of the user running VMware. Workaround The system administrator may create the file /tmp/rrdharan to prevent malicious users from creating a directory at that location: # touch /tmp/rrdharan Solution: All VMware Workstation users should upgrade to the latest version: # emerge --sync # emerge --ask --oneshot --verbose ">=app-emulation/vmware-workstation-4.5.2.8848-r5" Network Security Threat Level: Medium Networks Security ID: Vulnerability Assessment Copyright: (C) 2005 Michel Arboi |
||
Cables, Connectors |
ACASIS 2.5/3.5 inch 2 Bay SATA USB 3.0 Hard Drive Disk HDD SSD Enclosure 4 RAID
$58.99
Intel PCIe SSD AIC RAID Controller Card G97168-252
$44.55
Cisco UCS LSI MegaRAID 9271CV-8I SAS2308 PCIe SAS Internal RAID Controller
$28.00
Dell UCSA-901 0101A6100-000-G SAS PCI-E Raid Controller Card
$149.99
LSI MegaRAID 9361-8i 12Gb PCIe 8-Port SAS/SATA RAID 1Gb w/BBU/CacheVault/License
$39.95
LSI MegaRaid 9361-8i 12Gbps SAS / SATA Raid Controller PCIe x8 3.0 Tested
$29.00
Oracle Sun 8-Port 6 Gbps SAS/SATA Raid Controller PCIe w/Cables 7055240 7047503
$13.49
LSI 9271-8i MegaRAID 8-Port 6Gbps PCIe RAID Controller w/ 1Gb CacheVault & BBU
$30.99
G TECHNOLOGY G RAID 0G04228 2-Bay Thunderbolt 2 RAID Array W/Power Supply
$99.99
4 Bay RAID External Hard Drive Enclosure for 2.5/3.5" SATA HDD/SSD
$79.99
|
||
No Discussions have been posted on this vulnerability. |