VMware OVF Tool 3.x < 3.5.2 Multiple OpenSSL Vulnerabilities (VMSA-2014-0006) (Mac OS X)

Medium Nessus Plugin ID 77331

Synopsis

The remote Mac OS X host has an application installed that is affected by multiple vulnerabilities.

Description

The version of VMware OVF (Open Virtualization Format) Tool installed on the remote Mac OS X host is version 3.x prior to 3.5.2. It is, therefore, affected by multiple vulnerabilities in the bundled version of OpenSSL :

- An error exists in the 'ssl3_read_bytes' function that permits data to be injected into other sessions or allows denial of service attacks. Note that this issue is exploitable only if SSL_MODE_RELEASE_BUFFERS is enabled. (CVE-2010-5298)

- An error exists in the 'do_ssl3_write' function that permits a NULL pointer to be dereferenced, which could allow denial of service attacks. Note that this issue is exploitable only if SSL_MODE_RELEASE_BUFFERS is enabled. (CVE-2014-0198)

- An error exists in the processing of ChangeCipherSpec messages that allows the usage of weak keying material.
This permits simplified man-in-the-middle attacks to be done. (CVE-2014-0224)

- An error exists in the 'dtls1_get_message_fragment' function related to anonymous ECDH cipher suites. This could allow denial of service attacks. Note that this issue only affects OpenSSL TLS clients. (CVE-2014-3470)

Solution

Upgrade to VMware OVF Tool 3.5.2 or later.

See Also

http://www.vmware.com/security/advisories/VMSA-2014-0006.html

https://www.openssl.org/news/secadv/20140605.txt

Plugin Details

Severity: Medium

ID: 77331

File Name: macosx_vmware_ovftool_vmsa_2014_0006.nasl

Version: 1.6

Type: local

Agent: macosx

Published: 2014/08/20

Updated: 2018/07/14

Dependencies: 77330

Risk Information

Risk Factor: Medium

CVSS v2.0

Base Score: 6.8

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

Temporal Vector: CVSS2#E:F/RL:OF/RC:C

Vulnerability Information

CPE: cpe:/a:vmware:ovf_tool

Required KB Items: installed_sw/VMware OVF Tool

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/06/24

Vulnerability Publication Date: 2014/06/05

Exploitable With

Core Impact

Reference Information

CVE: CVE-2010-5298, CVE-2014-0198, CVE-2014-0224, CVE-2014-3470

BID: 66801, 67193, 67898, 67899

CERT: 978508

VMSA: 2014-0006