CVE-2008-0967: Medium severity vmware esxi vulnerability
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2008-0967?
The severity of CVE-2008-0967 is rated as medium due to the potential for local privilege escalation.
How do I fix CVE-2008-0967?
To fix CVE-2008-0967, update your VMware products to versions that have incorporated the patch for this vulnerability.
Which VMware versions are affected by CVE-2008-0967?
CVE-2008-0967 affects VMware Workstation 5.x, Player 1.x, Server 1.x, and certain ESX versions before their respective patched releases.
What is the impact of CVE-2008-0967?
The impact of CVE-2008-0967 allows an attacker to exploit the untrusted search path to execute arbitrary code with elevated privileges.
Is there a workaround for CVE-2008-0967?
A temporary workaround for CVE-2008-0967 includes adjusting system path variables to limit the search path that VMware applications utilize.