VMware ESXi 6.5 without patch ESXi650-201703410-SG and 5.5 without patch ESXi550-201703401-SG; Workstation Pro / Player 12.x prior to 12.5.5; and Fusion Pro / Fusion 8.x prior to 8.5.6 have a Heap Buffer Overflow in SVGA. This issue may allow a guest to execute code on the host.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/97163 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038148 | Third Party Advisory VDB Entry |
http://www.securitytracker.com/id/1038149 | Third Party Advisory VDB Entry |
http://www.vmware.com/security/advisories/VMSA-2017-0006.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
History
03 Feb 2022, 19:03
Type | Values Removed | Values Added |
---|---|---|
References | (SECTRACK) http://www.securitytracker.com/id/1038149 - Third Party Advisory, VDB Entry | |
References | (SECTRACK) http://www.securitytracker.com/id/1038148 - Third Party Advisory, VDB Entry | |
CPE | cpe:2.3:a:vmware:fusion:8.0.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.5.3:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.5.4:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.5.2:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.5.5:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.5.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.5.4:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.5.5:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.1.2:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.1.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.5.3:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.0.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.0.0:*:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:5.5:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.0.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.5.3:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.5.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.5.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.5.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.1.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.5.2:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.5.4:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.0.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.5.4:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.5.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.5.0:*:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:6.5:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.1.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.0.2:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.1.2:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:12.5.3:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:12.0.1:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:8.5.0:*:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:8.0.1:*:*:*:*:*:*:* |
cpe:2.3:o:vmware:esxi:6.5:650-201703002:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:6.5:650-201701001:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_pro:*:*:*:*:*:*:*:* cpe:2.3:a:vmware:workstation_player:*:*:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:5.5:3a:*:*:*:*:*:* cpe:2.3:o:apple:mac_os_x:-:*:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:5.5:-:*:*:*:*:*:* cpe:2.3:a:vmware:fusion:*:*:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:6.5:-:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:5.5:3b:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:5.5:1:*:*:*:*:*:* cpe:2.3:a:vmware:fusion_pro:*:*:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:5.5:2:*:*:*:*:*:* cpe:2.3:o:vmware:esxi:6.5:650-201703001:*:*:*:*:*:* |
Information
Published : 2017-06-07 18:29
Updated : 2024-02-04 19:29
NVD link : CVE-2017-4902
Mitre link : CVE-2017-4902
CVE.ORG link : CVE-2017-4902
JSON object : View
Products Affected
vmware
- esxi
- workstation_pro
- workstation_player
- fusion_pro
- fusion
apple
- mac_os_x
CWE
CWE-119
Improper Restriction of Operations within the Bounds of a Memory Buffer