Computer Security
[EN] securityvulns.ru
no-pyccku



CVECVE-2008-0923
StatusCandidate
DescriptionDirectory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.
PhaseAssigned (25.02.2008)
SecurityVulns:VMWare applications multiple security vulnerabilities
NVD:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0923
ReferencesBID : 27944
 BUGTRAQ : 20080225 CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation
 MISC : http://www.coresecurity.com/?action=item&id=2129
 SECTRACK : 1019493

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
 



Рейтинг@Mail.ru