CVE-2008-2098
published 2008-06-02CVE-2008-2098: Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build…
PriorityP426medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.46%
37.2th percentile
Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sharing is used, allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | ace_2 | — | — |
| vmware | ace_2 | — | — |
| vmware | esxi | — | — |
| vmware | fusion | — | — |
| vmware | fusion | — | — |
| vmware | vmware_fusion | — | — |
| vmware | vmware_player_2 | — | — |
| vmware | vmware_player_2 | — | — |
| vmware | vmware_player_2 | — | — |
| vmware | vmware_player_2 | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | vmware_workstation | — | — |
| vmware | workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2vrm-6v48-2rqp: Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6
ghsa_unreviewed·2022-05-01
CVE-2008-2098 [MEDIUM] CWE-119 GHSA-2vrm-6v48-2rqp: Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6
Heap-based buffer overflow in the VMware Host Guest File System (HGFS) in VMware Workstation 6 before 6.0.4 build 93057, VMware Player 2 before 2.0.4 build 93057, VMware ACE 2 before 2.0.2 build 93057, and VMware Fusion before 1.1.2 build 87978, when folder sharing is used, allows guest OS users to execute arbitrary code on the host OS via unspecified vectors.
VMware
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion resolve critical security issues
vendor_vmware·2008-05-30·CVSS 6.9
CVE-2008-2098 [MEDIUM] Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion resolve critical security issues
VMSA-2008-0008: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion resolve critical security issues
Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion resolve critical security issues VMware Security Advisory VMware Security AdvisoryAdvisory ID: VMware Security AdvisorySynopsis: Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion resolve critical security issues VMware Security AdvisoryIssue date: VMware Security AdvisoryUpdated on:
CVEs: CVE-2008-2098, CVE-2008-2099
Affected products: ESXi, VMware Fusion, VMware Workstation
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/30476http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/archive/1/492831/100/0/threadedhttp://www.securitytracker.com/id?1020148http://www.vmware.com/security/advisories/VMSA-2008-0008.htmlhttp://www.vupen.com/english/advisories/2008/1707/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42753http://secunia.com/advisories/30476http://security.gentoo.org/glsa/glsa-201209-25.xmlhttp://www.securityfocus.com/archive/1/492831/100/0/threadedhttp://www.securitytracker.com/id?1020148http://www.vmware.com/security/advisories/VMSA-2008-0008.htmlhttp://www.vupen.com/english/advisories/2008/1707/referenceshttps://exchange.xforce.ibmcloud.com/vulnerabilities/42753
2008-06-02
Published