CVE-2008-0923

Directory traversal vulnerability in the Shared Folders feature for VMWare ACE 1.0.2 and 2.0.2, Player 1.0.4 and 2.0.2, and Workstation 5.5.4 and 6.0.2 allows guest OS users to read and write arbitrary files on the host OS via a multibyte string that produces a wide character string containing .. (dot dot) sequences, which bypasses the protection mechanism, as demonstrated using a "%c0%2e%c0%2e" string.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.9 UNKNOWN
LOCAL
MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 2%
VendorProductVersion
vmwareace
1.0
vmwareace
1.0.2
vmwareace
2.0
vmwareace
2.0.1
vmwareace
2.0.2
vmwareplayer
1.0.4
vmwarevmware_player
1.0.1_build_19317:_build_19317
vmwarevmware_player
1.0.2
vmwarevmware_player
1.0.3
vmwarevmware_workstation
6.0.1
vmwarevmware_workstation
6.0.2
vmwareworkstation
4.5.2
vmwareworkstation
5.5.3_build_34685:_build_34685
vmwareworkstation
5.5.4
vmwareworkstation
6.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
vmware-player
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
gutsy
dne
feisty
ignored
edgy
ignored
dapper
ignored
vmware-server
karmic
dne
jaunty
dne
intrepid
dne
hardy
dne
gutsy
dne
feisty
ignored
edgy
dne
dapper
dne
References