• Sign in

CVE-2009-4811

    CVE-2009-4811  
Description VMware Authentication Daemon 1.0 in vmware-authd.exe in the VMware Authorization Service in VMware Workstation 7.0 before 7.0.1 build 227600 and 6.5.x before 6.5.4 build 246459, VMware Player 3.0 before 3.0.1 build 227600 and 2.5.x before 2.5.4 build 246459, VMware ACE 2.6 before 2.6.1 build 227600 and 2.5.x before 2.5.4 build 246459, and VMware Server 2.x allows remote attackers to cause a denial of service (process crash) via a \x25\x90 sequence in the USER and PASS commands, a related issue to CVE-2009-3707. NOTE: some of these details are obtained from third party information.
Impact
  CVSS v2 : 5 MEDIUM  
Type
  CWE-134  
Attack Vector
CVSSv2 Vector : AV:N/AC:L/Au:N/C:N/I:N/A:P
Quick linksCVE, NVD, CERT, Metasploit, Exploit-db, Fulldisc, Bugtraq, Microsoft, Red Hat, Debian, GitHub code/issues, Google
References
http://archives.neohapsis.com/archives/bugtraq/2010-04/0077.html
http://archives.neohapsis.com/archives/fulldisclosure/2010-04/0121.html
http://freetexthost.com/qr1tffkzpu
http://lists.vmware.com/pipermail/security-announce/2010/000090.html
http://pocoftheday.blogspot.com/2009/10/vmware-server-20x-remote-dos-exploit.html
http://security.gentoo.org/glsa/glsa-201209-25.xml
http://www.securityfocus.com/bid/36630
http://www.vmware.com/security/advisories/VMSA-2010-0007.html
  • FAQ
  • Terms of service
  • Privacy policy