4

VMware Security Advisory VMSA-2010-0007

VMware VMware Security AdvisoryAdvisory ID: VMSA-2010-0007Synopsis: VMware hosted products, vCenter Server and ESX patches resolve multiple security issuesIssue date: 2010-04-09Updated on: 2010-04-09 (initial release of advisory)CVE numbers: CVE-2010-1142 CVE-2010-1140 CVE-2009-2042 CVE-2009-1564 CVE-2009-1565 CVE-2009-3732 CVE-2009-3707 CVE-2010-1138 CVE-2010-1139 CVE-2010-1141- ————————————————————————-1. Summary VMware hosted products, vCenter Server and ESX patches resolve multiple security issues.2. Relevant releases VMware Workstation 7.0, VMware Workstation 6.5.3 and earlier, VMware Player 3.0, VMware Player 2.5.3 and earlier, VMware ACE 2.6, VMware ACE 2.5.3 and earlier, VMware Server 2.0.2 and earlier, VMware Fusion 3.0, VMware Fusion 2.0.6 and earlier, VMware VIX API for Windows 1.6.x, VMware ESXi 4.0 before patch ESXi400-201002402-BG VMware ESXi 3.5 before patch ESXe350-200912401-T-BG VMware ESX 4.0 without patches ESX400-201002401-BG, ESX400-200911223-UG VMware ESX 3.5 without patch ESX350-200912401-BG VMware ESX 3.0.3 without patch ESX303-201002203-UG VMware ESX 2.5.5 without Upgrade Patch 15. Notes: Effective May 2010, VMware’s patch and update release program during Extended Support will be continued with the condition that all subsequent patch and update releases will be based on the latest baseline release version as of May 2010 (i.e. ESX 3.0.3 Update 1, ESX 3.5 Update 5, and VirtualCenter 2.5 Update 6). Refer to section “End of Product Availability FAQs” at http://www.vmware.com/support/policies/lifecycle/vi/faq.html for details. Extended support for ESX 2.5.5 ends on 2010-06-15. Users should plan to upgrade to at least ESX 3.0.3 and preferably to the newest release available. Extended support for ESX 3.0.3 ends on 2011-12-10. Users should plan to upgrade to at least ESX 3.5 and preferably to the newest release available. End of General Support for VMware Workstation 6.x is 2011-04-27, users should plan to upgrade to the newest release available. End of General Support for VMware Server 2.0 is 2011-06-30, users should plan to upgrade to the newest release of either ESXi or VMware Player. Extended support for Virtual Center 2.0.2 is 2011-12-10, users should plan to upgrade to the newest release of vCenter Server.3. Problem Description a. Windows-based VMware Tools Unsafe Library Loading vulnerability A vulnerability in the way VMware libraries are referenced allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to lure the user that is logged on a Windows Guest Operating System to click on the attacker’s file on a network share. This file could be in any file format. The attacker will need to have the ability to host their malicious files on a network share. VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS Security (http://www.acrossecurity.com) for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2010-1141 to this issue. Steps needed to remediate this vulnerability: Guest systems on VMware Workstation, Player, ACE, Server, Fusion – Install the remediated version of Workstation, Player, ACE, Server and Fusion. – Upgrade tools in the virtual machine (virtual machine users will be prompted to upgrade). Guest systems on ESX 4.0, 3.5, 3.0.3, 2.5.5, ESXi 4.0, 3.5 – Install the relevant patches (see below for patch identifiers) – Manually upgrade tools in the virtual machine (virtual machine users will not be prompted to upgrade). Note the VI Client will not show the VMware tools is out of date in the summary tab. Please see http://tinyurl.com/27mpjo page 80 for details. The following table lists what action remediates the vulnerability (column 4) if a solution is available. See above for remediation details. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not affected Workstation 7.x any not affected Workstation 6.5.x any 6.5.4 build 246459 or later Player 3.x any not affected Player 2.5.x any 2.5.4 build 246459 or later ACE 2.6.x Windows not affected ACE 2.5.x Windows 2.5.4 build 246459 or later Server 2.x any 2.0.2 build 203138 or later Fusion 3.x Mac OS/X not affected Fusion 2.x Mac OS/X 2.0.6 build 246742 or later ESXi 4.0 ESXi ESXi400-201002402-BG ESXi 3.5 ESXi ESXe350-200912401-T-BG or later ESX 4.0 ESX ESX400-201002401-BG ESX 3.5 ESX ESX350-200912401-BG ESX 3.0.3 ESX ESX303-201002203-UG ESX 2.5.5 ESX Upgrade Patch 15 b. Windows-based VMware Tools Arbitrary Code Execution vulnerability A vulnerability in the way VMware executables are loaded allows for arbitrary code execution in the context of the logged on user. This vulnerability is present only on Windows Guest Operating Systems. In order for an attacker to exploit the vulnerability, the attacker would need to be able to plant their malicious executable in a certain location on the Virtual Machine of the user. On most recent versions of Windows (XP, Vista) the attacker would need to have administrator privileges to plant the malicious executable in the right location. Steps needed to remediate this vulnerability: See section 3.a. VMware would like to thank Mitja Kolsek of ACROS Security (http://www.acrossecurity.com) for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2010-1142 to this issue. Refer to the previous table in section 3.a for what action remediates the vulnerability (column 4) if a solution is available. See above for remediation details. c. Windows-based VMware Workstation and Player host privilege escalation A vulnerability in the USB service allows for a privilege escalation. A local attacker on the host of a Windows-based Operating System where VMware Workstation or VMware Player is installed could plant a malicious executable on the host and elevate their privileges. In order for an attacker to exploit the vulnerability, the attacker would need to be able to plant their malicious executable in a certain location on the host machine. On most recent versions of Windows (XP, Vista) the attacker would need to have administrator privileges to plant the malicious executable in the right location. VMware would like to thank Thierry Zoller for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2010-1140 to this issue. home repairs . The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not affected Workstation 7.0 Windows 7.0.1 build 227600 or later Workstation 7.0 Linux not affected Workstation 6.5.x any not affected Player 3.0 Windows 3.0.1 build 227600 or later Player 3.0 Linux not affected Player 2.5.x any not affected Ace any any not affected Server 2.x any not affected Fusion any Mac OS/X not affected ESXi any ESXi not affected ESX any ESX not affected d. Third party library update for libpng to version 1.2.37 The libpng libraries through 1.2.35 contain an uninitialized- memory-read bug that may have security implications. Specifically, 1-bit (2-color) interlaced images whose widths are not divisible by 8 may result in several uninitialized bits at the end of certain rows in certain interlace passes being returned to the user. An application that failed to mask these out-of-bounds pixels might display or process them, albeit presumably with benign results in most cases. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-2042 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not applicable Workstation 7.0 any 7.0.1 build 227600 or later Workstation 6.5.x any 6.5.4 build 246459 or later Player 3.0 any 3.0.1 build 227600 or later Player 2.5.x any 2.5.4 build 246459 or later Ace 2.6 Windows 2.6.1 build 227600 or later Ace 2.5.x Windows 2.5.4 build 246459 or later Server 2.x any not being fixed at this time Fusion any any Mac OS/X not affected ESXi any ESXi not applicable ESX any ESX not applicable e. VMware VMnc Codec heap overflow vulnerabilities The VMware movie decoder contains the VMnc media codec that is required to play back movies recorded with VMware Workstation, VMware Player and VMware ACE, in any compatible media player. The movie decoder is installed as part of VMware Workstation, VMware Player and VMware ACE, or can be downloaded as a stand alone package. Vulnerabilities in the decoder allow for execution of arbitrary code with the privileges of the user running an application utilizing the vulnerable codec. For an attack to be successful the user must be tricked into visiting a malicious web page or opening a malicious video file on a system that has the vulnerable version of the VMnc codec installed. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2009-1564 and CVE-2009-1565 to these issues. VMware would like to thank iDefense, Sebastien Renaud of VUPEN Vulnerability Research Team (http://www.vupen.com) and Alin Rad Pop of Secunia Research for reporting these issues to us. To remediate the above issues either install the stand alone movie decoder or update your product using the table below. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not affected Movie Decoder any Windows 6.5.4 Build 246459 or later Workstation 7.x any not affected Workstation 6.5.x Windows 6.5.4 build 246459 or later Workstation 6.5.x Linux not affected Player 3.x any not affected Player 2.5.x Windows 2.5.4 build 246459 or later Player 2.5.x Linux not affected ACE any any not affected Server 2.x Window not being addressed at this time Server 2.x Linux not affected Fusion any Mac OS/X not affected ESXi any ESXi not affected ESX any ESX not affectedf. VMware Remote Console format string vulnerability VMware Remote Console (VMrc) contains a format string vulnerability. Exploitation of this issue may lead to arbitrary code execution on the system where VMrc is installed. For an attack to be successful, an attacker would need to trick the VMrc user into opening a malicious Web page or following a malicious URL. Code execution would be at the privilege level of the user. VMrc is present on a system if the VMrc browser plug-in has been installed. This plug-in is required when using the console feature in WebAccess. Installation of the plug-in follows after visiting the console tab in WebAccess and choosing “Install plug-in”. The plug- in can only be installed on Internet Explorer and Firefox. Under the following two conditions your version of VMrc is likely to be affected: – the VMrc plug-in was obtained from vCenter 4.0 or from ESX 4.0 without patch ESX400-200911223-UG and – VMrc is installed on a Windows-based system The following steps allow you to determine if you have an affected version of VMrc installed: – Locate the VMrc executable vmware-vmrc.exe on your Windows-based system – Right click and go to Properties – Go to the tab “Versions” – Click “File Version” in the “Item Name” window – If the “Value” window shows “e.x.p build-158248″, the version of VMrc is affected Remediation of this issue on Windows-based systems requires the following steps (Linux-based systems are not affected): – Uninstall affected versions of VMrc from the systems where the VMrc plug-in has been installed (use the Windows Add/Remove Programs interface) – Install vCenter 4.0 Update 1 or install the ESX 4.0 patch ESX400-200911223-UG – Login into vCenter 4.0 Update 1 or ESX 4.0 with patch ESX400-200911223-UG using WebAccess on the system where the VMrc needs to be re-installed – Re-install VMrc by going to the console tab in WebAccess. The Console tab is selectable after selecting a virtual machine. Note: the VMrc plug-in for Firefox on Windows-based operating systems is no longer compatible after the above remediation steps. Users are advised to use the Internet Explorer VMrc plug-in. VMware would like to thank Alexey Sintsov from Digital Security Research Group for reporting this issue to us. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2009-3732 to this issue. g. Windows-based VMware authd remote denial of service A vulnerability in vmware-authd could cause a denial of service condition on Windows-based hosts. The denial of service is limited to a crash of authd. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-3707 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not affected Workstation 7.0 Windows 7.0.1 build 227600 or later Workstation 7.0 Linux not affected Workstation 6.5.x Windows 6.5.4 build 246459 or later Workstation 6.5.x Linux not affected Player 3.0 Windows 3.0.1 build 227600 or later Player 3.x Linux not affected Player 2.5.x Windows 2.5.4 build 246459 or later Player 2.5.x Linux not affected Ace 2.6 Windows 2.6.1 build 227600 or later Ace 2.5.x Windows 2.5.4 build 246459 or later Server 2.x Windows not being addressed at this time Server 2.x Linux not affected Fusion any Mac OS/X not affected ESXi any any not affected ESX any any not affected h. Potential information leak via hosted networking stack A vulnerability in the virtual networking stack of VMware hosted products could allow host information disclosure. Charter Communications . A guest operating system could send memory from the host vmware-vmx process to the virtual network adapter and potentially to the host’s physical Ethernet wire. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2010-1138 to this issue. VMware would like to thank Johann MacDonagh for reporting this issue to us. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not affected Workstation 7.0 any 7.0.1 build 227600 or later Workstation 6.5.x Windows 6.5.4 build 246459 or later Workstation 6.5.x Linux not affected Player 3.0 any 3.0.1 build 227600 or later Player 2.5.x Windows 2.5.4 build 246459 or later Player 2.5.x Linux not affected Ace 2.6 Windows 2.6.1 build 227600 or later Ace 2.5.x Windows 2.5.4 build 246459 or later Server 2.x any not being fixed at this time Fusion 3.0 Mac OS/X 3.0.1 build 232708 or later Fusion 2.x Mac OS/X 2.0.7 build 246742 or later ESXi any any not affected ESX any any not affected i. Linux-based vmrun format string vulnerability A format string vulnerability in vmrun could allow arbitrary code execution. If a vmrun command is issued and processes are listed, code could be executed in the context of the user listing the processes. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2010-1139 to this issue. VMware would like to thank Thomas Toth-Steiner for reporting this issue to us. The following table lists what action remediates the vulnerability (column 4) if a solution is available. VMware Product Running Replace with/ Product Version on Apply Patch ============= ======== ======= ================= VirtualCenter any Windows not affected VIX API any Windows not affected VIX API 1.6.x Linux upgrade to VIX API 1.7 or later VIX API 1.6.x Linux64 upgrade to VIX API 1.7 or later Workstation 7.x any not affected Workstation 6.5.x Windows not affected Workstation 6.5.x Linux 6.5.4 build 246459 or later Player 3.x any not affected Player 2.5.x Windows not affected Player 2.5.x Linux 2.5.4 build 246459 or later Ace any Windows not affected Server 2.x Windows not affected Server 2.x Linux not being fixed at this time Fusion 3.x Mac OS/X not affected Fusion 2.x Mac OS/X 2.0.7 build 246742 or later ESXi any any not affected ESX any any not affected4. Solution Please review the patch/release notes for your product and version and verify the md5sum and/or the sha1sum of your downloaded file.


1 Star2 Stars3 Stars4 Stars5 Stars (No Ratings Yet)
Loading ... Loading ...

About the Author

I am ben kevan.. Well yeah. .that's about it.

Comments (4)

Trackback URL | Comments RSS Feed

  1. Your material is great. I love to read intelligent articles and this is one reading I have really enjoyed. There’s no denying how much research you did for this content.

  2. companies says:

    You get an A+ from me on this article. I’m sure you aren’t looking for approval, but you have really made this content very interesting.

  3. I am thinking I need to consider some of the data you have in this article. I agree with a lot of your points. I’ll have to get my brain working on some of these.

  4. tree care says:

    You’ve made some excellent points in this article that I find very thought-provoking and stimulating. I am hoping for more from you soon. You just don’t find high quality writing like this very often online.

Leave a Reply




If you want a picture to show with your comment, go get a Gravatar.