SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Your Ad Here
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  Application (Generic)  >  VMware ESX Server Vendors:  VMware, Inc.
(VMware Issues Fix for ESX) LibTIFF Buffer Underflow in Decoding LZW Data Lets Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1021126
SecurityTracker URL:  http://securitytracker.com/id?1021126
CVE Reference:  CVE-2008-2327   (Links to External Site)
Updated:  Dec 3 2008
Original Entry Date:  Oct 31 2008
Impact:  Execution of arbitrary code via network, User access via network
Fix Available:  Yes   Vendor Confirmed:  Yes  
Version(s): 2.5.4, 2.5.5, 3.0.2, 3.0.3, 3.5
Description:  A vulnerability was reported in LibTIFF. A remote user can cause arbitrary code to be executed on the target user's system. VMware ESX is affected.

A remote user can create a specially crafted TIFF file that, when loaded by the target application using libTIFF, will trigger a buffer underflow and execute arbitrary code on the target system. The code will run with the privileges of the target application.

The vulnerability resides in 'tif_lzw.c'.

Drew Yao reported this vulnerability.

Impact:  A remote user can create a file that, when processed by the target application, will execute arbitrary code on the target system.
Solution:  VMware has issued a fix for ESX, which is affected by this vulnerability.

ESX 3.5 patch ESX350-200811405-SG
http://download3.vmware.com/software/vi/ESX350-200811 405-SG
md5sum: d6c676a6809a14268d7f95192a52ea21
http://kb.vmware.com/kb/1007503

ESX 3.0.3 patch ESX303-200810503-SG
http://download3.vmware.com/software/vi/ESX303-200810503-SG.zip
md5sum: e687313e58377be41f6e6b767dfbf268
http://kb.vmware.com/kb/1006971

ESX 3.0.2 patch ESX-1006968
http://download3.vmware.com/software/vi/ESX-1006968.tgz
md5sum: fc9e30cff6f03a209e6a275254fa6719
http://kb.vmware.com/kb/1006968

VMware ESX 2.5.5 Upgrade Patch 10
http://download3.vmware.com/software/esx/esx-2.5.5-119702-upgrade.tar.gz
md5sum: 2ee87cdd70b1ba84751e24c0bd8b4621
http://vmware.com/support/esx25/doc/esx-255-200810-patch.html

VMware ESX 2.5.4 Upgrade Patch 21
http://download3.vmware.com/software/esx/esx-2.5.4-119703-upgrade.tar.gz
md5sum: d791be525c604c852a03dd7df0eabf35
http://vmware.com/support/esx25/doc/esx-254-200810-patch.html

The VMware advisory is available at:

http://www.vmware.com/security/advisories/VMSA-2008-0017.html

Cause:  Boundary error
Reported By:  VMware Security Announcements <security-announce@lists.vmware.com>
Message History:   This archive entry is a follow-up to the message listed below.
Aug 26 2008 LibTIFF Buffer Underflow in Decoding LZW Data Lets Remote Users Execute Arbitrary Code



 Source Message Contents

Date:  Thu, 30 Oct 2008 23:26:00 -0700
From:  VMware Security Announcements <security-announce@lists.vmware.com>
Subject:  [Security-announce] VMSA-2008-0017 Updated ESX packages for libxml2,

 

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2008-0017
Synopsis:          Updated ESX packages for libxml2, ucd-snmp, libtiff
Issue date:        2008-10-31
Updated on:        2008-10-31 (initial release of advisory)
CVE numbers:       CVE-2008-3281 CVE-2008-0960 CVE-2008-2327
- ------------------------------------------------------------------------

1. Summary

   Updated ESX packages for libxml2, ucd-snmp, libtiff

2. Relevant releases

   ESX 3.0.3 without patch ESX303-200810503-SG
   ESX 3.0.2 without patch ESX-1006968
   ESX 2.5.5 before Upgrade Patch 10
   ESX 2.5.4 before Upgrade Patch 21

   NOTE: Extended support (Security and Bug fixes) for ESX 3.0.2 ended
         on 2008-10-29. Extended support (Security and Bug fixes) for
         ESX 2.5.4 ended on 2008-10-08.

         Extended support for ESX 3.0.2 Update 1 ends on 2009-08-08. Users
         should plan to upgrade to ESX 3.0.3 and preferably to the newest
         release available.

3. Problem Description

 a. Updated ESX Service Console package libxml2

    A denial of service flaw was found in the way libxml2 processes
    certain content. If an application that is linked against
    libxml2 processes malformed XML content, the XML content might
    cause the application to stop responding.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-3281 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted         any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            3.5       ESX      affected, patch pending
    ESX            3.0.3     ESX      ESX303-200810503-SG
    ESX            3.0.2     ESX      ESX-1006968
    ESX            2.5.5     ESX      ESX 2.5.5 upgrade patch 10 or later
    ESX            2.5.4     ESX      ESX 2.5.4 upgrade patch 21

    * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 b. Updated ESX Service Console package ucd-snmp

    A flaw was found in the way ucd-snmp checks an SNMPv3 packet's
    Keyed-Hash Message Authentication Code. An attacker could use
    this flaw to spoof an authenticated SNMPv3 packet.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-0960 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted         any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      ESX 2.5.5 upgrade patch 10 or later
    ESX            2.5.4     ESX      ESX 2.5.4 upgrade patch 21

    * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 c. Updated third party library libtiff

    Multiple uses of uninitialized values were discovered in libtiff's
    Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker
    could create a carefully crafted LZW-encoded TIFF file that would
    cause an application linked with libtiff to crash or, possibly,
    execute arbitrary code.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-2327 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted         any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      ESX 2.5.5 upgrade patch 10 or later
    ESX            2.5.4     ESX      ESX 2.5.4 upgrade patch 21

    * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

4. Solution

   Please review the patch/release notes for your product and version
   and verify the md5sum of your downloaded file.

   ESX
   ---
   ESX 3.0.3 patch ESX303-200810503-SG
   http://download3.vmware.com/software/vi/ESX303-200810503-SG.zip
   md5sum: e687313e58377be41f6e6b767dfbf268
   http://kb.vmware.com/kb/1006971

   ESX 3.0.2 patch ESX-1006968
   http://download3.vmware.com/software/vi/ESX-1006968.tgz
   md5sum: fc9e30cff6f03a209e6a275254fa6719
   http://kb.vmware.com/kb/1006968

   VMware ESX 2.5.5 Upgrade Patch 10
   http://download3.vmware.com/software/esx/esx-2.5.5-119702-upgrade.tar.gz
   md5sum: 2ee87cdd70b1ba84751e24c0bd8b4621
   http://vmware.com/support/esx25/doc/esx-255-200810-patch.html

   VMware ESX 2.5.4 Upgrade Patch 21
   http://download3.vmware.com/software/esx/esx-2.5.4-119703-upgrade.tar.gz
   md5sum: d791be525c604c852a03dd7df0eabf35
   http://vmware.com/support/esx25/doc/esx-254-200810-patch.html

5. References

   CVE numbers
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3281
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-0960
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-2327

- ------------------------------------------------------------------------
6. Change log

2008-10-31  VMSA-2008-0017
Initial security advisory after release of ESX 3.0.3, ESX 3.0.2, ESX
2.5.5 and ESX 2.5.4 patches on 2008-10-30.

- -----------------------------------------------------------------------
7. Contact

E-mail list for product security notifications and announcements:
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce

This Security Advisory is posted to the following lists:

  * security-announce at lists.vmware.com
  * bugtraq at securityfocus.com
  * full-disclosure at lists.grok.org.uk

E-mail:  security at vmware.com
PGP key at: http://kb.vmware.com/kb/1055

VMware Security Center
http://www.vmware.com/security

VMware security response policy
http://www.vmware.com/support/policies/security_response.html

General support life cycle policy
http://www.vmware.com/support/policies/eos.html

VMware Infrastructure support life cycle policy
http://www.vmware.com/support/policies/eos_vi.html

Copyright 2008 VMware Inc.  All rights reserved.

-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8

wj8DBQFJCqTjS2KysvBH1xkRAqquAJ95Glo5kh8hbHiCPmOVqCnjtGZp9QCfRkFk
LBRW6mL3i4I5CK4D8sg7StQ=
=nJyw
-----END PGP SIGNATURE-----

_______________________________________________
Security-announce mailing list
Security-announce@lists.vmware.com
http://lists.vmware.com/mailman/listinfo/security-announce

 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2007, SecurityGlobal.net LLC