Release date:
Updated on:
Affected Systems:
VMWare Workstation 7.x
VMWare Workstation 6.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47094
Cve id: CVE-2011-1126
The VMware vix api allows you to compile software and scripts for automated virtual machine operations, run programs, or manage files in the client operating system. VMware Workstation is a powerful desktop virtual computer software that allows users to run different operating systems simultaneously on a single desktop, and the best solution for developing, testing, and deploying new applications.
On the Linux platform, VMware "vmrun" has a local privilege escalation vulnerability. Attackers can exploit this vulnerability to escalate privileges.
This vulnerability occurs when the vmrun program mistakenly loads libraries from some directories, causing arbitrary code execution with the user permissions currently running vmrun to load malicious shared libraries.
<* Source: Tim Brown (securityfocus@machine.org.uk)
Link: http://marc.info /? L = full-disclosure & m = 130146421004752 & w = 2
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com