[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2010-1138Date: (C)2010-04-12   (M)2023-12-22


The virtual networking stack in VMware Workstation 7.0 before 7.0.1 build 227600, VMware Workstation 6.5.x before 6.5.4 build 246459 on Windows, VMware Player 3.0 before 3.0.1 build 227600, VMware Player 2.5.x before 2.5.4 build 246459 on Windows, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware Server 2.x, and VMware Fusion 3.0 before 3.0.1 build 232708 and 2.x before 2.0.7 build 246742 allows remote attackers to obtain sensitive information from memory on the host OS by examining received network packets, related to interaction between the guest OS and the host vmware-vmx process.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.0
Exploit Score: 10.0
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECTRACK-1023836
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
SECUNIA-39203
SECUNIA-39206
SECUNIA-39215
BID-39395
OSVDB-63607
GLSA-201209-25
http://lists.vmware.com/pipermail/security-announce/2010/000090.html
http://www.vmware.com/security/advisories/VMSA-2010-0007.html

CPE    14
cpe:/a:vmware:player:3.0
cpe:/a:vmware:server:2.0.0
cpe:/a:vmware:workstation:7.0
cpe:/o:microsoft:windows
...
CWE    1
CWE-200

© SecPod Technologies