CVE-2008-0967
Last modified
CVE-2008-0967 is a vulnerability of currently unknown severity. Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.. EPSS estimates a 0.36% chance of exploitation in the next 30 days.
Description
Untrusted search path vulnerability in vmware-authd in VMware Workstation 5.x before 5.5.7 build 91707 and 6.x before 6.0.4 build 93057, VMware Player 1.x before 1.0.7 build 91707 and 2.x before 2.0.4 build 93057, and VMware Server before 1.0.6 build 91891 on Linux, and VMware ESXi 3.5 and VMware ESX 2.5.4 through 3.5, allows local users to gain privileges via a library path option in a configuration file.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Esx Server | 2.5.5 |
| Vmware | Esx Server | 3.1 |
| Vmware | Esx Server | 3.2 |
| Vmware | Esx Server | 3.3 |
| Vmware | Esx Server | 3.5 |
| Vmware | Esxi | 3.5 |
| Vmware | Player | 1.0.0 |
| Vmware | Player | 1.0.1 |
| Vmware | Player | 1.0.2 |
| Vmware | Player | 1.0.3 |
| Vmware | Player | 1.0.4 |
| Vmware | Player | 1.0.5 |
| Vmware | Player | 1.0.6 |
| Vmware | Player | 2.0 |
| Vmware | Player | 2.0.1 |
| Vmware | Player | 2.0.2 |
| Vmware | Player | 2.0.3 |
| Vmware | Server | 1.0.3 |
| Vmware | Vmware Server | 1.0.0 |
| Vmware | Vmware Server | 1.0.1 |
| Vmware | Vmware Server | 1.0.2 |
| Vmware | Vmware Server | 1.0.4 |
| Vmware | Vmware Server | 1.0.5 |
| Vmware | Vmware Workstation | 5.5.0 |
| Vmware | Vmware Workstation | 5.5.2 |
| Vmware | Vmware Workstation | 5.5.5 |
| Vmware | Vmware Workstation | 5.5.6 |
| Vmware | Vmware Workstation | 6.0.1 |
| Vmware | Vmware Workstation | 6.0.2 |
| Vmware | Vmware Workstation | 6.0.3 |
| Vmware | Workstation | 5.5.1 |
| Vmware | Workstation | 5.5.3 |
| Vmware | Workstation | 5.5.4 |
| Vmware | Workstation | 6.0 |
| Vmware | Esx | 3.0.0 |
| Vmware | Esx | 3.0.1 |
| Vmware | Esx | 3.0.2 |
References
- http://secunia.com/advisories/30556Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1744Vendor Advisory
- http://secunia.com/advisories/30556Vendor Advisory
- http://www.vupen.com/english/advisories/2008/1744Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-0967?
How severe is CVE-2008-0967?
How do I fix CVE-2008-0967?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2008
- CVE-2008-0960SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.…
- CVE-2008-0961EMV DiskXtender 6.20.060 has a hard-coded login and password…9.8
- CVE-2008-0962Stack-based buffer overflow in the File System Manager for E…
- CVE-2008-0963Format string vulnerability in EMC DiskXtender MediaStor 6.2…
- CVE-2008-0964Multiple stack-based buffer overflows in snoop on Sun Solari…
- CVE-2008-0965Multiple format string vulnerabilities in snoop on Sun Solar…
- CVE-2008-0971Multiple cross-site scripting (XSS) vulnerabilities in index…
- CVE-2008-0973Buffer overflow in Double-Take (aka HP StorageWorks Storage …
- CVE-2008-0974Double-Take 5.0.0.2865 and earlier, distributed under the HP…
- CVE-2008-0975Double-Take 5.0.0.2865 and earlier, distributed under the HP…
- CVE-2008-0976Double-Take 5.0.0.2865 and earlier, distributed under the HP…
- CVE-2008-0977Double-Take 5.0.0.2865 and earlier, distributed under the HP…
Are you affected by CVE-2008-0967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
