Vulnerability Name:

CVE-2009-3282 (CCN-53617)

Assigned:2009-10-01
Published:2009-10-01
Updated:2009-10-20
Summary:Integer overflow in the vmx86 kernel extension in VMware Fusion before 2.0.6 build 196839 allows host OS users to cause a denial of service to the host OS via unspecified vectors.
Per: http://lists.vmware.com/pipermail/security-announce/2009/000066.html

Solution

Please review the patch/release notes for your product and version
and verify the md5sum and/or the sha1sum of your downloaded file.

VMware Fusion 2.0.6 (for Intel-based Macs): Download including
VMware Fusion and a 12 month complimentary subscription to McAfee
VirusScan Plus 2009

md5sum: d35490aa8caa92e21339c95c77314b2f
sha1sum: 9c41985d754ac718032a47af8a3f98ea28fddb26

VMware Fusion 2.0.6 (for Intel-based Macs): Download including only
VMware Fusion software

md5sum: 2e8d39defdffed224c4bab4218cc6659
sha1sum: 453d54a2f37b257a0aad17c95843305250c7b6ef

CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:7.8 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C)
5.8 Medium (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-189
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2009-3282

Source: CCN
Type: VMSA-2009-0013
VMware Fusion resolves two security issues

Source: MLIST
Type: Vendor Advisory
[security-announce] 20091001 VMSA-2009-0013 VMware Fusion resolves two security issues

Source: CCN
Type: SA36928
VMware Fusion Denial of Service and Privilege Escalation

Source: SECUNIA
Type: Vendor Advisory
36928

Source: CCN
Type: SECTRACK ID: 1022981
VMware Fusion vmx86 Kernel Extension Bugs Let Local Host OS Users Gain Elevated Privileges and Deny Service on the Host System

Source: SECTRACK
Type: UNKNOWN
1022981

Source: CCN
Type: OSVDB ID: 58476
VMware Fusion vmx86 Kernel Extension Unspecified Overflow DoS

Source: CCN
Type: BID-36579
VMware Fusion Local Denial Of Service Vulnerability

Source: CONFIRM
Type: Vendor Advisory
http://www.vmware.com/security/advisories/VMSA-2009-0013.html

Source: VUPEN
Type: Vendor Advisory
ADV-2009-2811

Source: XF
Type: UNKNOWN
fusion-vmx86-dos(53617)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:vmware:fusion:1.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:1.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:1.1.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:1.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:1.1.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0.2:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0.4:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:*:*:*:*:*:*:*:* (Version <= 2.0.5)
  • AND
  • cpe:/o:apple:mac_os_x:*:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:vmware:fusion:2.0.3:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0.5:*:*:*:*:*:*:*
  • OR cpe:/a:vmware:fusion:2.0.4:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    vmware fusion 1.0
    vmware fusion 1.1
    vmware fusion 1.1.1
    vmware fusion 1.1.2
    vmware fusion 1.1.3
    vmware fusion 2.0
    vmware fusion 2.0.1
    vmware fusion 2.0.2
    vmware fusion 2.0.3
    vmware fusion 2.0.4
    vmware fusion *
    apple mac os x *
    vmware fusion 2.0.3
    vmware fusion 2.0
    vmware fusion 2.0.5
    vmware fusion 2.0.4