First published: Fri Sep 21 2007(Updated: )
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Workstation | >=5.5<5.5.5 | |
VMware Workstation | >=6.0<6.0.1 | |
VMware Player | >=2.0<2.0.1 | |
VMware ACE | >=2.0<2.0.1 | |
VMware ESX | =2.5.4 | |
VMware ESX | =2.5.3 | |
VMware ESX | =2.1.3 | |
VMware ESX | =2.0.2 | |
VMware ESX | =3.0.0 | |
VMware ESX | =3.0.1 | |
VMware ACE | >=1.0<1.0.3 | |
VMware Player | >=1.0<1.0.5 | |
VMware Server | >=1.0<1.0.4 | |
Ubuntu Linux | =6.06 | |
Ubuntu Linux | =7.04 | |
Ubuntu Linux | =6.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-0063 has a medium severity rating due to its potential to allow unauthorized access to network resources.
To fix CVE-2007-0063, upgrade VMware Workstation, Player, ACE, or Server to the patched versions specified in the security advisories.
CVE-2007-0063 affects various versions of VMware Workstation, Player, ACE, Server, and certain versions of VMware ESX.
CVE-2007-0063 is classified as an integer underflow vulnerability impacting the DHCP server functionality.
While the primary solution for CVE-2007-0063 is to apply updates, temporarily disabling DHCP services may serve as a workaround.