|
Brought to you by:
Suppliers of:
|
|
|
| |
| A vulnerability has been discovered in various VMWare products, which can be exploited by malicious people to compromise a user's system. This vulnerability is caused due to a boundary error in the VMnc codec (vmnc.dll) and can be exploited to cause a heap-based buffer overflow via a specially crafted video file with mismatched dimensions. |
| |
Credit:
The information has been provided by Alin Rad Pop.
The original article can be found at: http://secunia.com/secunia_research/2009-25/
|
| |
Vulnerable Systems:
* VMWare Workstation version 6.5.2 build 156735
Immune Systems:
* VMWare Workstation version 6.5.3 build 185404
CVE Information:
CVE-2009-0199
Disclosure Timeline:
30/04/2009 - Vendor notified.
30/04/2009 - Vendor response.
21/08/2009 - Patched VMware Workstation, Player, and ACE released.
04/09/2009 - Patched VMware Workstation Movie Decoder released.
07/09/2009 - Public disclosure.
--------------------------------------------------------------------------------------------------------------------------------
Find out more about SQL injection and eliminate the opportunity to exploit it on your site.
-
|
|
|
|
|