CVE-2007-0063

VMware ESX - Remote Code Execution via DHCP Server Integer Underflow

Title source: llm
STIX 2.1

Description

Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 55017, and Server before 1.0.4 Build 56528 allows remote attackers to execute arbitrary code via a malformed DHCP packet that triggers a stack-based buffer overflow.

References (18)

Core 18
Core References
Third Party Advisory mailing-list x_refsource_fulldisc
http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html
Patch, Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/25729
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200711-23.xml
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/usn-543-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/33103
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id?1018717
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/3229
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27694
Patch, Third Party Advisory third-party-advisory x_refsource_iss
http://www.iss.net/threats/275.html
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/server/doc/releasenotes_server.html
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/ace2/doc/releasenotes_ace2.html
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/player2/doc/releasenotes_player2.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/26890
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/ace/doc/releasenotes_ace.html
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/player/doc/releasenotes_player.html
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/ws6/doc/releasenotes_ws6.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/27706
Patch, Vendor Advisory x_refsource_confirm
http://www.vmware.com/support/ws55/doc/releasenotes_ws55.html

Scores

EPSS 0.0774
EPSS Percentile 92.0%

Details

CWE
CWE-191
Status published
Products (13)
canonical/ubuntu_linux 6.06
canonical/ubuntu_linux 6.10
canonical/ubuntu_linux 7.04
vmware/ace 1.0 - 1.0.3
vmware/esx 2.0.2
vmware/esx 2.1.3
vmware/esx 2.5.3
vmware/esx 2.5.4
vmware/esx 3.0.0
vmware/esx 3.0.1
... and 3 more
Published Sep 21, 2007
Tracked Since Feb 18, 2026