Secunia Research has discovered two vulnerabilities in multiple VMWare products, which can be exploited by malicious people to compromise a vulnerable system. The vulnerabilities are caused by two integer truncation errors in vmnc.dll when processing HexTile encoded video chunks and can be exploited to cause heap-based buffer overflows. Successful exploitation may allow execution of arbitrary code by tricking a user into opening a specially crafted AVI file.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/88218/secunia-vmwareit.txt
Source: https://packetstormsecurity.com/files/88218/VMWare-VMnc-Codec-HexTile-Encoding-Integer-Truncation.html

