10
CVSSv2

CVE-2007-0063

Published: 21/09/2007 Updated: 16/07/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Integer underflow in the DHCP server in EMC VMware Workstation prior to 5.5.5 Build 56455 and 6.x prior to 6.0.1 Build 55017, Player prior to 1.0.5 Build 56455 and Player 2 prior to 2.0.1 Build 55017, ACE prior to 1.0.3 Build 54075 and ACE 2 prior to 2.0.1 Build 55017, and Server prior to 1.0.4 Build 56528 allows remote malicious users to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.

Vulnerable Product Search on Vulmon Subscribe to Product

vmware player

vmware workstation

vmware esx 3.0.1

vmware esx 2.0.2

vmware esx 2.1.3

vmware esx 2.5.3

vmware esx 2.5.4

vmware ace

vmware server

vmware esx 3.0.0

canonical ubuntu linux 6.10

canonical ubuntu linux 6.06

canonical ubuntu linux 7.04

Vendor Advisories

Neel Mehta and Ryan Smith discovered that the VMWare Player DHCP server did not correctly handle certain packet structures Remote attackers could send specially crafted packets and gain root privileges (CVE-2007-0061, CVE-2007-0062, CVE-2007-0063) ...