VMSA-2008-0003 : Moderate: Updated aacraid driver and samba and python Service Console updates

High Nessus Plugin ID 40374

Synopsis

The remote VMware ESX host is missing one or more security-related patches.

Description

I Updated ESX driver

a. Updated aacraid driver

This patch fixes a flaw in how the aacraid SCSI driver checked IOCTL command permissions. This flaw might allow a local user on the Service Console to cause a denial of service or gain privileges. Thanks to Adaptec for reporting this issue.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-4308 to this issue.

II Service Console package security updates

a. Samba

Alin Rad Pop of Secunia Research found a stack-based buffer overflow flaw in the way Samba authenticates remote users. A remote unauthenticated user could trigger this flaw to cause the Samba server to crash or to execute arbitrary code with the permissions of the Samba server.

Note: This vulnerability can be exploited only if the attacker has access to the Service Console network. The Samba client is installed by default in the Service Console, but the Samba server is not.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-6015 to this issue.

b. Python

Chris Evans of the Google security research team discovered an integer overflow issue with the way Python's Perl-Compatible Regular Expression (PCRE) module handled certain regular expressions. If a Python application used the PCRE module to compile and execute untrusted regular expressions, it might be possible to cause the application to crash, or to execute arbitrary code with the privileges of the Python interpreter.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2006-7228 to this issue.

Piotr Engelking discovered a flaw in Python's locale module where strings generated by the strxfrm() function were not properly NUL-terminated. This might result in disclosure of data stored in the memory of a Python application using the strxfrm() function.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-2052 to this issue.

Slythers Bro reported multiple integer overflow flaws in Python's imageop module. These could allow an attacker to cause a Python application to crash, enter an infinite loop, or possibly execute arbitrary code with the privileges of the Python interpreter.

The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-4965 to this issue.

Solution

Apply the missing patches.

See Also

http://lists.vmware.com/pipermail/security-announce/2008/000012.html

Plugin Details

Severity: High

ID: 40374

File Name: vmware_VMSA-2008-0003.nasl

Version: 1.19

Type: local

Published: 2009/07/27

Updated: 2018/08/06

Dependencies: 12634

Risk Information

Risk Factor: High

CVSS v2.0

Base Score: 9.3

Temporal Score: 7.3

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/o:vmware:esx:2.5.4, cpe:/o:vmware:esx:2.5.5, cpe:/o:vmware:esx:3.0.1, cpe:/o:vmware:esx:3.0.2, cpe:/o:vmware:esx:3.5

Required KB Items: Host/local_checks_enabled, Host/VMware/release, Host/VMware/version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2008/02/04

Vulnerability Publication Date: 2007/03/31

Reference Information

CVE: CVE-2006-7228, CVE-2007-2052, CVE-2007-4308, CVE-2007-4965, CVE-2007-6015

BID: 23887, 25216, 25696, 26462, 26727, 26791

VMSA: 2008-0003

CWE: 119, 189