Friday, October 1, 2010

VMware Workstation , Player and ACE: several security issues addressed

Users of VMware Workstation, Player and ACE please be advised of a several security issues addressed vulnerability that has been identified.

To view this vulnerability, possible remedies, and others please check out the Security Advisories at Critical Watch (http://criticalwatch.com/support/security-advisories.aspx)

Amplify’d from www.criticalwatch.com
VMSA-2010-0014: VMware Workstation, Player, and ACE - several security issues addressed
Problem Description



a. VMware Workstation and Player installer security issue



The Workstation 7.x and Player 3.x installers will load an index.htm

file located in the current working directory on which Workstation

7.x or Player 3.x is being installed. This may allow an attacker to

display a malicious file if they manage to get their file onto the

system prior to installation.
b. Third party libpng updated to version 1.2.44



A buffer overflow condition in libpng is addressed that could

potentially lead to code execution with the privileges of the

application using libpng. Two potential denial of service issues

are also addressed in the update.
c. VMware ACE Management Server (AMS) for Windows updates Apache httpd

version 2.2.15.



A function in Apache HTTP Server when multithreaded MPM is used

does not properly handle headers in subrequests in certain

circumstances which may allow remote attackers to obtain sensitive

information via a crafted request that triggers access to memory

locations associated with an earlier request.
Read more at www.criticalwatch.com
 

No comments:

Post a Comment