MEDIUM
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .
Published Feb 26, 2008
6.9
MEDIUMCVSS 2.0
EPSS 0.49%
Description
Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.
Affected products
No data.
OR
- 1.0
- 1.0.2
- 2.0
- 2.0.1
- 2.0.2
- 1.0.4
- 1.0.1_build_19317
- 1.0.2
- 1.0.3
- 6.0.1
- 6.0.2
- 4.5.2
- 5.5.3_build_34685
- 5.5.4
- 6.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (20)
- http://kb.vmware.com/selfservice/microsites/search.do?language=en_US&cmd=displayKC&externalId=1004034 x_refsource_CONFIRM
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-February/060457.html mailing-listx_refsource_FULLDISC
- http://lists.vmware.com/pipermail/security-announce/2008/000008.html mailing-listx_refsource_MLIST
- http://secunia.com/advisories/29117 third-party-advisoryx_refsource_SECUNIA
- http://securityreason.com/securityalert/3700 third-party-advisoryx_refsource_SREASON
- http://www.coresecurity.com/?action=item&id=2129 x_refsource_MISC
- http://www.securityfocus.com/archive/1/488725/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/archive/1/489739/100/0/threaded mailing-listx_refsource_BUGTRAQ
- http://www.securityfocus.com/bid/27944 vdb-entryx_refsource_BID
- http://www.securityfocus.com/bid/28276 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id?1019493 vdb-entryx_refsource_SECTRACK
- http://www.vmware.com/security/advisories/VMSA-2008-0005.html x_refsource_CONFIRM
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html x_refsource_CONFIRM
- http://www.vmware.com/support/player/doc/releasenotes_player.html x_refsource_CONFIRM
- http://www.vmware.com/support/player2/doc/releasenotes_player2.html x_refsource_CONFIRM
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html x_refsource_CONFIRM
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html x_refsource_CONFIRM
- http://www.vupen.com/english/advisories/2008/0679 vdb-entryx_refsource_VUPEN
- http://www.vupen.com/english/advisories/2008/0905/references vdb-entryx_refsource_VUPEN
- https://exchange.xforce.ibmcloud.com/vulnerabilities/40837 vdb-entryx_refsource_XF
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 26, 2008
Updated Aug 7, 2024
Reserved Feb 25, 2008
Link CVE-2008-0923
CISA Vulnrichment
Updated n/a