Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 146377 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.901020
Kategorie:Buffer overflow
Titel:VMware Products Multiple Vulnerabilities (VMSA-2009-0012) - Windows
Zusammenfassung:VMWare products are prone to multiple vulnerabilities.
Beschreibung:Summary:
VMWare products are prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple flaws exist due to:

- An heap overflow error in the VMnc codec (vmnc.dll) when processing a video
file with mismatched dimension.

- An heap corruption error in the VMnc codec (vmnc.dll) when processing a video
with a height of less than 8 pixels.

Vulnerability Impact:
Successful exploitation will allow attacker to cause a heap-based buffer
overflow via a specially crafted video file with mismatched dimensions.

Affected Software/OS:
VMware Workstation versions prior to 6.5.3 Build 185404
VMware Player versions prior to 2.5.3 build 185404

Solution:
Upgrade the VMWare product(s) according to the referenced vendor announcement.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-0199
BugTraq ID: 36290
http://www.securityfocus.com/bid/36290
Bugtraq: 20090905 VMSA-2009-0012 VMware Movie Decoder, VMware Workstation, VMware Player, and VMware ACE resolve security issues. (Google Search)
http://www.securityfocus.com/archive/1/506286/100/0/threaded
http://secunia.com/secunia_research/2009-25/
http://lists.vmware.com/pipermail/security-announce/2009/000065.html
http://secunia.com/advisories/34938
http://www.vupen.com/english/advisories/2009/2553
Common Vulnerability Exposure (CVE) ID: CVE-2009-2628
CERT/CC vulnerability note: VU#444513
http://www.kb.cert.org/vuls/id/444513
CopyrightCopyright (C) 2009 Greenbone AG

Dies ist nur einer von 146377 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.