| Title | 複数の VMware 製品の vmware-authd における権限を取得される脆弱性 |
|---|---|
| Summary | 複数の VMware 製品の vmware-authd には、権限を取得される脆弱性が存在します。 |
| Possible impacts | ローカルユーザにより、設定ファイル内の library path オプションを介して、権限を取得される可能性があります。 |
| Solution | ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。 |
| Publication Date | June 4, 2008, midnight |
| Registration Date | Sept. 13, 2010, 4:02 p.m. |
| Last Update | Sept. 13, 2010, 4:02 p.m. |
| CVSS2.0 : 警告 | |
| Score | 6.9 |
|---|---|
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
| VMware |
| VMware ESX 2.5.4 |
| VMware ESX 2.5.5 |
| VMware ESX 3.0.1 |
| VMware ESX 3.0.2 |
| VMware ESX 3.5 |
| VMware ESXi 3.5 |
| VMware Player 1.x |
| VMware Player 2.x |
| VMware Server 1.x |
| VMware Workstation 5.x |
| VMware Workstation 6.x |
| No | Changed Details | Date of change |
|---|---|---|
| 0 | [2010年09月13日] 掲載 |
Feb. 17, 2018, 10:37 a.m. |
| Summary | Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file. |
|---|---|
| Summary | Vulnerabilidad de ruta de búsqueda no confiable en vmware-authd en VMware Workstation versión 5.x anterior a 5.5.7 build 91707 y versión 6.x anterior a 6.0.4 build 93057, VMware Player versión 1.x anterior a 1.0.7 build 91707 y versión 2.x anterior a 2.0.4 build 93057, y VMware Server anterior a 1.0.6 build 91891 en Linux, y VMware ESXi versión 3.5 y VMware ESX versión 2.5.4 hasta 3.5, permite a los usuarios locales obtener privilegios por medio de una opción de path library en un archivo de configuración. |
| Publication Date | June 6, 2008, 5:32 a.m. |
| Registration Date | Jan. 29, 2021, 1:32 p.m. |
| Last Update | April 23, 2026, 9:35 a.m. |
| Configuration1 | or higher | or less | more than | less than | |
| cpe:2.3:a:vmware:esx_server:2.5.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:esx_server:3.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:esx_server:3.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:esx_server:3.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:esx_server:3.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:esxi:3.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:1.0.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:2.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:2.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:2.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:player:2.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:server:1.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_server:1.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_server:1.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_server:1.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_server:1.0.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_server:1.0.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:5.5.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:5.5.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:5.5.5:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:5.5.6:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:6.0.2:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:vmware_workstation:6.0.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:workstation:5.5.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:workstation:5.5.3:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:workstation:5.5.4:*:*:*:*:*:*:* | |||||
| cpe:2.3:a:vmware:workstation:6.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:vmware:esx:3.0.0:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:vmware:esx:3.0.1:*:*:*:*:*:*:* | |||||
| cpe:2.3:o:vmware:esx:3.0.2:*:*:*:*:*:*:* | |||||