CVE-2007-0063
Last modified
CVE-2007-0063 is a vulnerability of currently unknown severity. Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.. EPSS estimates a 20.41% chance of exploitation in the next 30 days.
Description
Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Ace | >= 1.0, < 1.0.3 |
| Vmware | Ace | >= 2.0, < 2.0.1 |
| Vmware | Player | >= 1.0, < 1.0.5 |
| Vmware | Player | >= 2.0, < 2.0.1 |
| Vmware | Server | >= 1.0, < 1.0.4 |
| Vmware | Workstation | >= 5.5, < 5.5.5 |
| Vmware | Workstation | >= 6.0, < 6.0.1 |
| Vmware | Esx | 2.0.2 |
| Vmware | Esx | 2.1.3 |
| Vmware | Esx | 2.5.3 |
| Vmware | Esx | 2.5.4 |
| Vmware | Esx | 3.0.0 |
| Vmware | Esx | 3.0.1 |
| Canonical | Ubuntu Linux | 6.06 |
| Canonical | Ubuntu Linux | 6.10 |
| Canonical | Ubuntu Linux | 7.04 |
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlThird Party Advisory
- http://secunia.com/advisories/26890Third Party Advisory
- http://secunia.com/advisories/27694Third Party Advisory
- http://secunia.com/advisories/27706Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200711-23.xmlThird Party Advisory
- http://www.iss.net/threats/275.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/25729Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018717Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-543-1Third Party Advisory
- http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3229Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33103Third Party Advisory, VDB Entry
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.htmlThird Party Advisory
- http://secunia.com/advisories/26890Third Party Advisory
- http://secunia.com/advisories/27694Third Party Advisory
- http://secunia.com/advisories/27706Third Party Advisory
- http://security.gentoo.org/glsa/glsa-200711-23.xmlThird Party Advisory
- http://www.iss.net/threats/275.htmlPatch, Third Party Advisory
- http://www.securityfocus.com/bid/25729Patch, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1018717Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/usn-543-1Third Party Advisory
- http://www.vmware.com/support/ace/doc/releasenotes_ace.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ace2/doc/releasenotes_ace2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player/doc/releasenotes_player.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/player2/doc/releasenotes_player2.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/server/doc/releasenotes_server.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws55/doc/releasenotes_ws55.htmlPatch, Vendor Advisory
- http://www.vmware.com/support/ws6/doc/releasenotes_ws6.htmlPatch, Vendor Advisory
- http://www.vupen.com/english/advisories/2007/3229Third Party Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/33103Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-0063?
How severe is CVE-2007-0063?
How do I fix CVE-2007-0063?
Are you affected by CVE-2007-0063?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
