CVE-2008-0967

3 documents3 sources
Severity
6.9MEDIUM
EPSS
0.1%
top 78.12%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 5
Latest updateMay 1

Description

Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 3.4 | Impact: 10.0

Affected Packages8 packages

NVDvmware/esxi3.5
NVDvmware/player11 versions+10
NVDvmware/server1.0.3
NVDvmware/esx_server5 versions+4
NVDvmware/workstation4 versions+3

🔴Vulnerability Details

2
GHSA
GHSA-w7jw-whgf-5mgf: Untrusted search path vulnerability in vmware-authd in VMware Workstation 52022-05-01
CVEList
CVE-2008-0967: Untrusted search path vulnerability in vmware-authd in VMware Workstation 52008-06-05
CVE-2008-0967 (MEDIUM CVSS 6.9) | Untrusted search path vulnerability | cvebase.io