VMware Fusion 10.x < 10.1.6 / 11.x < 11.0.3 Multiple Vulnerabilities (VMSA-2019-0005) (macOS)

medium Nessus Plugin ID 124299

Synopsis

A virtualization application installed on the remote macOS or Mac OS X host is affected by an uninitialized stack memory usage vulnerability.

Description

The version of VMware Fusion installed on the remote macOS or Mac OS X host is 10.x prior to 10.1.6 or 11.x prior to 11.0.3. It is, therefore, affected by multiple vulnerabilities, including:

- An out-of-bounds read vulnerability exists in the vertex shader component of the 3D-acceleration feature could allow an authenticated attacker to disclose sensitive information or cause a denial-of-service of the guest virtual machine. (CVE-2019-5516)

- An out-of-bounds read vulnerability exists in the shader translator component of the 3D-acceleration feature could allow an authenticated attacker to disclose sensitive information or cause a denial-of-service of the guest virtual machine. (CVE-2019-5517)

- An out-of-bounds read vulnerability in the 3D-acceleration feature could allow an authenticated attacker to disclose sensitive information.
(CVE-2019-5520)

Note virtual machines must be configured with the 3D-acceleration enabled. VMware Fusion defaults to this feature being enabled.

Solution

Upgrade to VMware Fusion version 10.1.6, 11.0.3, or later.

See Also

https://www.vmware.com/security/advisories/VMSA-20189-0006.html

Plugin Details

Severity: Medium

ID: 124299

File Name: macosx_fusion_vmsa_2019_0006.nasl

Version: 1.3

Type: local

Agent: macosx

Published: 4/25/2019

Updated: 10/30/2019

Supported Sensors: Nessus Agent

Risk Information

VPR

Risk Factor: Medium

Score: 5.2

CVSS v2

Risk Factor: Medium

Base Score: 5.8

Temporal Score: 4.3

Vector: AV:N/AC:M/Au:N/C:P/I:N/A:P

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2019-5516

CVSS v3

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:vmware:fusion

Required KB Items: Host/local_checks_enabled, installed_sw/VMware Fusion

Exploit Ease: No known exploits are available

Patch Publication Date: 4/11/2019

Vulnerability Publication Date: 4/11/2019

Reference Information

CVE: CVE-2019-5516, CVE-2019-5517, CVE-2019-5520

BID: 107878, 107879, 107880

VMSA: 2019-0006

IAVA: 2019-A-0134