Ubuntu Security Notice USN-543-1
15th November, 2007
linux-restricted-modules-2.6.17/20, vmware-player-kernel-2.6.15 vulnerabilities
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 7.04
- Ubuntu 6.10
- Ubuntu 6.06 LTS
Software description
- linux-restricted-modules-2.6.17
- linux-restricted-modules-2.6.20
- vmware-player-kernel-2.6.15
Details
Neel Mehta and Ryan Smith discovered that the VMWare Player DHCP server
did not correctly handle certain packet structures. Remote attackers
could send specially crafted packets and gain root privileges.
(CVE-2007-0061, CVE-2007-0062, CVE-2007-0063)
Rafal Wojtczvk discovered multiple memory corruption issues in VMWare
Player. Attackers with administrative privileges in a guest operating
system could cause a denial of service or possibly execute arbitrary
code on the host operating system. (CVE-2007-4496, CVE-2007-4497)
Update instructions
The problem can be corrected by updating your system to the following package version:
- Ubuntu 7.04:
- vmware-tools-kernel-modules-2.6.20-16 2.6.20.6-16.30
- vmware-server-kernel-modules-2.6.20-16 2.6.20.6-16.30
- vmware-player-kernel-modules-2.6.20-16 2.6.20.6-16.30
- Ubuntu 6.10:
- vmware-player-kernel-modules-2.6.17-12 2.6.17.9-12.4
- Ubuntu 6.06 LTS:
- vmware-player-kernel-modules-2.6.15-29 2.6.15.11-13
To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
References
CVE-2007-0061, CVE-2007-0062, CVE-2007-0063, CVE-2007-4496, CVE-2007-4497