Summary
The remote host is missing updates announced in
advisory GLSA 201209-25.
Solution
Gentoo discontinued support for VMware Player. We recommend that users unmerge VMware Player:
# emerge --unmerge 'app-emulation/vmware-player'
NOTE: Users could upgrade to > =app-emulation/vmware-player-3.1.5, however these packages are not currently stable.
Gentoo discontinued support for VMware Workstation. We recommend that users unmerge VMware Workstation:
# emerge --unmerge 'app-emulation/vmware-workstation'
NOTE: Users could upgrade to > =app-emulation/vmware-workstation-7.1.5, however these packages are not currently stable.
Gentoo discontinued support for VMware Server. We recommend that users unmerge VMware Server:
# emerge --unmerge 'app-emulation/vmware-server'
http://www.securityspace.com/smysecure/catid.html?in=GLSA%20201209-25 http://bugs.gentoo.org/show_bug.cgi?id=213548
http://bugs.gentoo.org/show_bug.cgi?id=224637
http://bugs.gentoo.org/show_bug.cgi?id=236167
http://bugs.gentoo.org/show_bug.cgi?id=245941
http://bugs.gentoo.org/show_bug.cgi?id=265139
http://bugs.gentoo.org/show_bug.cgi?id=282213
http://bugs.gentoo.org/show_bug.cgi?id=297367
http://bugs.gentoo.org/show_bug.cgi?id=335866
http://bugs.gentoo.org/show_bug.cgi?id=385727
Insight
Multiple vulnerabilities have been found in VMware Player, Server, and Workstation, allowing remote and local attackers to conduct several attacks, including privilege escalation, remote execution of arbitrary code, and a Denial of Service.
Severity
Classification
-
CVSS Base Score: 10.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
Related Vulnerabilities