CVE-2007-0061
published 2007-09-21CVE-2007-0061: The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1…
PriorityP350critical10CVSS 2.0
AVNACLAuNCCICAC
EPSS
6.50%
93.0th percentile
The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."
Affected
16 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| vmware | ace | >= 1.0 < 1.0.3 | 1.0.3 |
| vmware | ace | >= 2.0 < 2.0.1 | 2.0.1 |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | esx | — | — |
| vmware | player | >= 1.0 < 1.0.5 | 1.0.5 |
| vmware | player | >= 2.0 < 2.0.1 | 2.0.1 |
| vmware | server | >= 1.0 < 1.0.4 | 1.0.4 |
| vmware | workstation | >= 5.5 < 5.5.5 | 5.5.5 |
| vmware | workstation | >= 6.0 < 6.0.1 | 6.0.1 |
CVSS provenance
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
vendor_redhat10.0CRITICAL
vendor_ubuntu10.0CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
VMWare vulnerabilities
vendor_ubuntu·2007-11-15·CVSS 10.0
CVE-2007-0062 [CRITICAL] VMWare vulnerabilities
Title: VMWare vulnerabilities
Summary: VMWare vulnerabilities
Neel Mehta and Ryan Smith discovered that the VMWare Player DHCP server
did not correctly handle certain packet structures. Remote attackers
could send specially crafted packets and gain root privileges.
(CVE-2007-0061, CVE-2007-0062, CVE-2007-0063)
Rafal Wojtczvk discovered multiple memory corruption issues in VMWare
Player. Attackers with administrative privileges in a guest operating
system could cause a denial of service or possibly execute arbitrary
code on the host operating system. (CVE-2007-4496, CVE-2007-4497)
Instructions: After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Red Hat
CVE-2007-0061: The DHCP server in EMC VMware Workstation before 5
vendor_redhat·CVSS 10.0
CVE-2007-0061 [CRITICAL] CVE-2007-0061: The DHCP server in EMC VMware Workstation before 5
The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."
Statement: Not vulnerable. This issue did not affect the versions of dhcp as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.
GHSA
GHSA-xmcp-6wwf-qfhc: The DHCP server in EMC VMware Workstation before 5
ghsa_unreviewed·2022-05-01
CVE-2007-0061 [HIGH] CWE-119 GHSA-xmcp-6wwf-qfhc: The DHCP server in EMC VMware Workstation before 5
The DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed packet that triggers "corrupt stack memory."
No detection rules found.
No public exploits indexed.
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://secunia.com/advisories/26890http://secunia.com/advisories/27694http://secunia.com/advisories/27706http://security.gentoo.org/glsa/glsa-200711-23.xmlhttp://www.iss.net/threats/275.htmlhttp://www.securityfocus.com/bid/25729http://www.securitytracker.com/id?1018717http://www.ubuntu.com/usn/usn-543-1http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2007/3229https://exchange.xforce.ibmcloud.com/vulnerabilities/33101http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlhttp://secunia.com/advisories/26890http://secunia.com/advisories/27694http://secunia.com/advisories/27706http://security.gentoo.org/glsa/glsa-200711-23.xmlhttp://www.iss.net/threats/275.htmlhttp://www.securityfocus.com/bid/25729http://www.securitytracker.com/id?1018717http://www.ubuntu.com/usn/usn-543-1http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlhttp://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlhttp://www.vmware.com/support/player/doc/releasenotes_player.htmlhttp://www.vmware.com/support/player2/doc/releasenotes_player2.htmlhttp://www.vmware.com/support/server/doc/releasenotes_server.htmlhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlhttp://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlhttp://www.vupen.com/english/advisories/2007/3229https://exchange.xforce.ibmcloud.com/vulnerabilities/33101
2007-09-21
Published