VMware Fusion update fixes two holes

By Tom Espiner, ZDNet UK
Monday, October 05, 2009 09:06 AM

An update for VMware's Fusion software has patched two vulnerabilities that could allow a hacker to control or crash a user's computer.

Fusion allows VMware customers to run Windows applications on Intel-based Macs. The flaws affect all versions of the software running on Mac OS X prior to and including 2.0.5.

In an advisory published on Thursday, VMware warned that the two vulnerabilities affect the kernel of the software. One, a kernel code execution flaw, is caused by a file permission problem in the vmx86 kernel extension. The other, an integer overflow bug in the vmx86 kernel extension, could lead to a successful denial-of-service attack, the virtualization specialist said.

An attacker does not need administrative privileges to target these security holes.

VMware advised customers running the software on Mac OS X to download Fusion version 2.0.6 from VMware downloads. Customers may be entitled to a 12-month free subscription to McAfee VirusScan Plus 2009, depending on their version of Fusion. They should review their product release notes to verify whether they can get the free subscription, according to the advisory.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web