VMware Workspace Portal Multiple Bash Shell Vulnerabilities (VMSA-2014-0010) (Shellshock)

Critical Nessus Plugin ID 78857


The remote host has a device management application installed that is affected by multiple vulnerabilities.


The version of VMware Workspace Portal (formerly known as VMware Horizon Workspace) installed on the remote host is missing package updates. It is, therefore, affected by the following vulnerabilities in the Bash shell :

- A command injection vulnerability exists in GNU Bash known as Shellshock, which is due to the processing of trailing strings after function definitions in the values of environment variables. This allows a remote attacker to execute arbitrary code via environment variable manipulation depending on the configuration of the system. By sending a specially crafted request to a CGI script that passes environment variables, a remote, unauthenticated attacker can execute arbitrary code on the host. (CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169)

- An out-of-bounds memory access error exists due to improper redirection implementation in the 'parse.y' source file. A remote attacker can exploit this issue to cause a denial of service or potentially execute arbitrary code. (CVE-2014-7186)

- An off-by-one error exists in the 'read_token_word' function in the 'parse.y' source file. A remote attacker can exploit this issue to cause a denial of service or potentially execute arbitrary code. (CVE-2014-7187)


Apply the relevant patch as stated in the 2091067 VMware KB advisory.

See Also





Plugin Details

Severity: Critical

ID: 78857

File Name: vmware_workspace_portal_vmsa2014-0010.nasl

Version: $Revision: 1.14 $

Type: remote

Family: Misc.

Published: 2014/11/04

Modified: 2017/06/12

Dependencies: 77958, 12634

Risk Information

Risk Factor: Critical


Base Score: 10

Temporal Score: 9

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: CVSS2#E:POC/RL:ND/RC:ND

Vulnerability Information

CPE: x-cpe:/a:vmware:vmware_horizon_workspace, x-cpe:/a:vmware:vmware_workspace_portal

Required KB Items: Host/local_checks_enabled, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2014/10/03

Vulnerability Publication Date: 2014/09/24

Exploitable With

Core Impact

Metasploit (CUPS Filter Bash Environment Variable Code Injection (Shellshock))

Reference Information

CVE: CVE-2014-6271, CVE-2014-6277, CVE-2014-6278, CVE-2014-7169, CVE-2014-7186, CVE-2014-7187

BID: 70103, 70137, 70152, 70154, 70165, 70166

OSVDB: 112004, 112096, 112097, 112158, 112169

VMSA: 2014-0010

IAVA: 2014-A-0142

CERT: 252743

EDB-ID: 34765, 34766, 34777