First published: Fri Oct 16 2009(Updated: )
VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\xFF sequence in the USER and PASS commands, related to a "format string DoS" issue. NOTE: some of these details are obtained from third party information.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
VMware Player | =3.0.1 | |
VMware Player | =2.5.4 | |
VMware ACE | =2.5.2 | |
VMware ACE | =2.5.1 | |
VMware Player | =2.5.1 | |
VMware ACE | =2.6.1 | |
VMware Player | =3.0 | |
VMware Player | =2.5.2 | |
VMware Workstation | =7.0 | |
VMware ACE | =2.6 | |
VMware Workstation | =6.5.1 | |
VMware ACE | =2.5.3 | |
VMware Workstation | =6.5.4 | |
VMware Server | =2.0.0 | |
VMware Workstation | =6.5.0 | |
VMware Player | =2.5 | |
VMware ACE | =2.5.4 | |
VMware Workstation | =7.0.1 | |
VMware Server | =2.0.1 | |
VMware Workstation | =6.5.2 | |
VMware ACE | =2.5.0 | |
VMware Workstation | =6.5.3 | |
VMware Server | =2.0.2 | |
VMware Player | =2.5.3 | |
=2.5.0 | ||
=2.5.1 | ||
=2.5.2 | ||
=2.5.3 | ||
=2.5.4 | ||
=2.6 | ||
=2.6.1 | ||
=2.5 | ||
=2.5.1 | ||
=2.5.2 | ||
=2.5.3 | ||
=2.5.4 | ||
=3.0 | ||
=3.0.1 | ||
=2.0.0 | ||
=2.0.1 | ||
=2.0.2 | ||
=6.5.0 | ||
=6.5.1 | ||
=6.5.2 | ||
=6.5.3 | ||
=6.5.4 | ||
=7.0 | ||
=7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2009-3707 is classified as a security vulnerability that could allow unauthorized access to the VMware Authentication Daemon.
To fix CVE-2009-3707, upgrade VMware Workstation to version 7.0.1 or later, or to VMware Player version 3.0.1 or later.
CVE-2009-3707 affects VMware Workstation versions prior to 7.0.1, VMware Player versions prior to 3.0.1, and several versions of VMware ACE.
Yes, CVE-2009-3707 can potentially be exploited remotely if the VMware services are exposed.
A temporary workaround for CVE-2009-3707 is to restrict network access to the VMware services until an upgrade can be applied.