Security bypass in VMware Fusion - CVE-2016-5329

 

Security bypass in VMware Fusion - CVE-2016-5329

Published: October 26, 2016 / Updated: October 31, 2016


Vulnerability identifier: #VU1101
CSH Severity: Low
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-5329
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to bypass security restrictions on the target system.
The weakness is due to access control flaw. By obtaining kernel memory address information, a local attacker can bypass address space layout randomization (ASLR) security protections.
Successful exploitation of the vulnerability results in access to the vulnerable system.

Affected software

VMware Fusion
SUSE Linux Enterprise Micro
gdk-pixbuf-debugsource
typelib-1_0-GdkPixbuf-2_0
libgdk_pixbuf-2_0-0
gdk-pixbuf-query-loaders-debuginfo
gdk-pixbuf-query-loaders
libgdk_pixbuf-2_0-0-debuginfo

How to mitigate CVE-2016-5329

Update to version 8.5.

gdk-pixbuf-debugsource - update to 2.42.12-150400.5.9.1
typelib-1_0-GdkPixbuf-2_0 - update to 2.42.12-150400.5.9.1
libgdk_pixbuf-2_0-0 - update to 2.42.12-150400.5.9.1
gdk-pixbuf-query-loaders-debuginfo - update to 2.42.12-150400.5.9.1
gdk-pixbuf-query-loaders - update to 2.42.12-150400.5.9.1
libgdk_pixbuf-2_0-0-debuginfo - update to 2.42.12-150400.5.9.1

External References

Related Security Bulletins