Gentoo: vmware-server env variable vulnerability
Summary
GENTOO LINUX SECURITY ANNOUNCEMENT 200308-03
- From advisory: "By manipulating the VMware GSX Server and VMware Workstation environment variables, a program such as a shell session with root privileges could be started when a virtual machine is launched. The user would then have full access to the host."
Read the full advisories at:
SOLUTION
It is recommended that all Gentoo Linux users who are running app-emulation/vmware-workstation upgrade to either vmware-workstation-3.2.1-2242 or vmware-workstation-4.0.1-5289 follows:
emerge sync emerge vmware-workstation-emerge clean
aliz@gentoo.org - GnuPG key is available at
Resolution
References
Availability
Concerns
Background