CVE-2008-4914
published 2009-02-03CVE-2008-4914: Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial…
PriorityP48medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.32%
24.5th percentile
Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial of service (host crash) via a snapshot with a malformed VMDK delta disk.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | esx | — | — |
| vmware | esxi | — | — |
| vmware | vmware_esxi | — | — |
| vmware | vmware_tools | — | — |
| vmware | vmware_workstation | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-26wx-wm74-72f9: Unspecified vulnerability in VMware ESXi 3
ghsa_unreviewed·2022-05-17
CVE-2008-4914 [MEDIUM] GHSA-26wx-wm74-72f9: Unspecified vulnerability in VMware ESXi 3
Unspecified vulnerability in VMware ESXi 3.5 before ESXe350-200901401-I-SG and ESX 3.5 before ESX350-200901401-SG allows local administrators to cause a denial of service (host crash) via a snapshot with a malformed VMDK delta disk.
VMware
ESX patches address an issue loading corrupt virtual disks and update Service Console packages
vendor_vmware·2009-01-30·CVSS 4.7
CVE-2008-4225 [MEDIUM] ESX patches address an issue loading corrupt virtual disks and update Service Console packages
VMSA-2009-0001: ESX patches address an issue loading corrupt virtual disks and update Service Console packages
a. Loading a corrupt delta disk may cause ESX to crash If the VMDK delta disk of a snapshot is corrupt, an ESX host might crash when the corrupted disk is loaded. VMDK delta files exist for virtual machines with one or more snapshots. This change ensures that a corrupt VMDK delta file cannot be used to crash ESX hosts. A corrupt VMDK delta disk, or virtual machine would have to be loaded by an administrator. VMware would like to thank Craig Marshall for reporting this issue. The Common Vulnerabilities and Exposures project ( cve.mitre.org) has assigned the name CVE-2008-4914 to this issue. The following table lists what action remediates the vulnerability (column 4) if a solution
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://secunia.com/advisories/33776http://www.securityfocus.com/bid/33549http://www.securitytracker.com/id?1021654http://www.vmware.com/security/advisories/VMSA-2009-0001.htmlhttp://www.vupen.com/english/advisories/2009/0301https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5909http://secunia.com/advisories/33776http://www.securityfocus.com/bid/33549http://www.securitytracker.com/id?1021654http://www.vmware.com/security/advisories/VMSA-2009-0001.htmlhttp://www.vupen.com/english/advisories/2009/0301https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5909
2009-02-03
Published