Vulnerability Name: CVE-2008-1364 (CCN-41254) Assigned: 2008-03-17 Published: 2008-03-17 Updated: 2018-10-11 Summary: Unspecified vulnerability in the DHCP service in VMware Workstation 5.5.x before 5.5.6, VMware Player 1.0.x before 1.0.6, VMware ACE 1.0.x before 1.0.5, VMware Server 1.0.x before 1.0.5, and VMware Fusion 1.1.x before 1.1.1 allows attackers to cause a denial of service. CVSS v3 Severity: 2.8 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L )Exploitability Metrics: Attack Vector (AV): LocalAttack Complexity (AC): LowPrivileges Required (PR): LowUser Interaction (UI): RequiredScope: Scope (S): UnchangedImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Low
CVSS v2 Severity: 7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C )5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): NetworkAccess Complexity (AC): LowAuthentication (Au): NoneImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Complete
1.7 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P )1.3 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:P/E:U/RL:OF/RC:C )Exploitability Metrics: Access Vector (AV): LocalAccess Complexity (AC): LowAthentication (Au): Single_InstanceImpact Metrics: Confidentiality (C): NoneIntegrity (I): NoneAvailibility (A): Partial
Vulnerability Type: CWE-noinfo CWE-399 Vulnerability Consequences: Denial of Service References: Source: MITRE Type: CNACVE-2008-1364 Source: MLIST Type: Patch[security-announce] 20080317 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues Source: CCN Type: SA29412VMware Server Multiple Vulnerabilities Source: CCN Type: SA29413VMware Products Multiple Vulnerabilities Source: GENTOO Type: UNKNOWNGLSA-201209-25 Source: SREASON Type: UNKNOWN3755 Source: CCN Type: SECTRACK ID: 1019623VMware Unspecified DHCP Bug Lets Users Deny Service Source: SECTRACK Type: UNKNOWN1019623 Source: CCN Type: OSVDB ID: 43900VMware Multiple Products DHCP Service Unspecified DoS Source: BUGTRAQ Type: UNKNOWN20080318 VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues Source: BID Type: UNKNOWN28276 Source: CCN Type: BID-28276VMware Server 1.0.5 and Workstation 6.0.3 Multiple Vulnerabilities Source: BID Type: UNKNOWN28289 Source: CCN Type: BID-28289VMware Products Multiple Vulnerabilities Source: CCN Type: VMSA-2008-0005Several critical security vulnerabilities have been addressed in the newest releases of VMware's hosted product line. Source: CONFIRM Type: Patchhttp://www.vmware.com/security/advisories/VMSA-2008-0005.html Source: CONFIRM Type: Patchhttp://www.vmware.com/support/fusion/doc/releasenotes_fusion.html Source: CONFIRM Type: Patchhttp://www.vmware.com/support/player/doc/releasenotes_player.html Source: CONFIRM Type: Patchhttp://www.vmware.com/support/server/doc/releasenotes_server.html Source: CONFIRM Type: Patchhttp://www.vmware.com/support/ws55/doc/releasenotes_ws55.html Source: VUPEN Type: UNKNOWNADV-2008-0905 Source: XF Type: UNKNOWNvmware-dhcp-unspecified-dos(41254) Source: XF Type: UNKNOWNvmware-dhcp-unspecified-dos(41254) Vulnerable Configuration: Configuration 1 :cpe:/a:vmware:ace:1.0:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:2.0:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.4:*:*:*:*:*:*:* OR cpe:/a:vmware:player:1.0.5:*:*:*:*:*:*:* OR cpe:/a:vmware:player:2.0:*:*:*:*:*:*:* OR cpe:/a:vmware:player:2.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:player:2.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_server:1.0.4:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_workstation:5.5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_workstation:6.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:vmware_workstation:6.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_42958:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4_build_44386:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:6.0:*:*:*:*:*:*:* Configuration CCN 1 :cpe:/a:vmware:workstation:6.0:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:2.0:*:*:*:*:*:*:* OR cpe:/a:vmware:ace:1.0:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.3:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_34685:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.3_build_42958:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.4_build_44386:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:5.5.5:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:6.0.1:*:*:*:*:*:*:* OR cpe:/a:vmware:workstation:6.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.2:*:*:*:*:*:*:* OR cpe:/a:vmware:server:1.0.4:*:*:*:*:*:*:* Denotes that component is vulnerable BACK
vmware ace 1.0
vmware ace 2.0
vmware player 1.0.2
vmware player 1.0.3
vmware player 1.0.4
vmware player 1.0.5
vmware player 2.0
vmware player 2.0.1
vmware player 2.0.2
vmware server 1.0.3
vmware vmware server 1.0.2
vmware vmware server 1.0.4
vmware vmware workstation 5.5.5
vmware vmware workstation 6.0.1
vmware vmware workstation 6.0.2
vmware workstation 5.5
vmware workstation 5.5.3_build_34685
vmware workstation 5.5.3_build_42958
vmware workstation 5.5.4
vmware workstation 5.5.4_build_44386
vmware workstation 6.0
vmware workstation 6.0
vmware ace 2.0
vmware ace 1.0
vmware server 1.0.3
vmware workstation 5.5
vmware workstation 5.5.3_build_34685
vmware workstation 5.5.3_build_42958
vmware workstation 5.5.4
vmware workstation 5.5.4_build_44386
vmware workstation 5.5.5
vmware workstation 6.0.1
vmware workstation 6.0.2
vmware server 1.0.2
vmware server 1.0.4