MEDIUM · 6.9

CVE-2008-0967

Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4...

Vulnerability Description

Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.

CVSS Score

6.9

MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
VmwareEsx Server2.5.5
VmwareEsxi3.5
VmwarePlayer1.0.0
VmwareServer1.0.3
VmwareVmware Server1.0.0
VmwareVmware Workstation5.5.0
VmwareWorkstation5.5.1
VmwareEsx3.0.0

References

FAQ

What is CVE-2008-0967?

CVE-2008-0967 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4...

How severe is CVE-2008-0967?

CVE-2008-0967 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2008-0967?

Check the references section above for vendor advisories and patch information. Affected products include: Vmware Esx Server, Vmware Esxi, Vmware Player, Vmware Server, Vmware Vmware Server.