Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2012-3569

Overview

Vulnerability Score 9.3 9.3
CVE Id CVE-2012-3569
Last Modified 17 Aug 2013 02:47:03
Published 14 Nov 2012 07:30:59
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity MEDIUM
Authentication NONE

CVE-2012-3569

Summary

Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Player 4.x before 4.0.5, and other products, allows user-assisted remote attackers to execute arbitrary code via a crafted OVF file.

Vulnerable Systems

Application

  • Vmware Ovf Tool 2.1

  • Vmware Player 4.0

  • Vmware Player 4.0.0.18997

  • Vmware Player 4.0.1

  • Vmware Player 4.0.2

  • Vmware Player 4.0.3

  • Vmware Player 4.0.4

  • Vmware Workstation 8.0

  • Vmware Workstation 8.0.0.18997

  • Vmware Workstation 8.0.1

  • Vmware Workstation 8.0.1.27038

  • Vmware Workstation 8.0.2

  • Vmware Workstation 8.0.3

  • Vmware Workstation 8.0.4


References

CONFIRM - http://www.vmware.com/security/advisories/VMSA-2012-0015.html

XF - vmware-ovf-format-string(79922)

MISC - http://technet.microsoft.com/en-us/security/msvr/msvr13-002

SECUNIA - 51240

MISC - http://packetstormsecurity.com/files/120101/VMWare-OVF-Tools-Format-String.html

OSVDB - 87117

Related Patches

VMware VMSA-2013-0002 VMSA-2012-0015 VMware Workstation 8.0.5 for Windows (Update) (All Languages) (See Notes) (Rev 3)

VMware VMSA-2012-0015 VMware Player 4.0.5 for Windows (Update) (All Languages) (See Notes) (Rev 2)


Last Updated: 27 May 2016 10:58:27