CVE-2017-4907

VMware Unified Access Gateway (2.5.x, 2.7.x, 2.8.x prior to 2.8.1) and Horizon View (7.x prior to 7.1.0, 6.x prior to 6.2.4) contain a heap buffer-overflow vulnerability which may allow a remote attacker to execute code on the security gateway.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:vmware:horizon_view:6.0:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.0.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.1.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.2.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.2.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.2.3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:6.2.4:*:*:*:*:*:*:*
cpe:2.3:a:vmware:horizon_view:7.0:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:vmware:unified_access_gateway:2.5:*:*:*:*:*:*:*
cpe:2.3:a:vmware:unified_access_gateway:2.5.1:*:*:*:*:*:*:*
cpe:2.3:a:vmware:unified_access_gateway:2.7:*:*:*:*:*:*:*
cpe:2.3:a:vmware:unified_access_gateway:2.7.2:*:*:*:*:*:*:*
cpe:2.3:a:vmware:unified_access_gateway:2.8:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () http://www.securityfocus.com/bid/97914 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/97914 - Third Party Advisory, VDB Entry
References () http://www.securitytracker.com/id/1038281 - () http://www.securitytracker.com/id/1038281 -
References () http://www.vmware.com/security/advisories/VMSA-2017-0008.html - Vendor Advisory () http://www.vmware.com/security/advisories/VMSA-2017-0008.html - Vendor Advisory

Information

Published : 2017-06-08 13:29

Updated : 2024-11-21 03:26


NVD link : CVE-2017-4907

Mitre link : CVE-2017-4907

CVE.ORG link : CVE-2017-4907


JSON object : View

Products Affected

vmware

  • horizon_view
  • unified_access_gateway
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer