New User, Welcome!     Login

<< Previous Next >>

The Common Vulnerabilities and Exposures

VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues

    Player 3.x is being installed. Installed versions of Workstation and
    Player are not affected. The security issue is no longer present in
    the installer of the new versions of Workstation 7.x and Player 3.x
    (see table below for the version numbers).

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-3277 to this issue.

    VMware would like to thank Alexander Trofimov and Marc Esher for
    independently reporting this issue to VMware.


VMSA-2010-0019 VMware ESX third party updates for Service Console

 a. Service Console update for samba

    The service console package samba is updated to version
    3.0.9-1.3E.18.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-3069 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.  

VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap

 a. Service Console update for glibc

    The service console packages glibc, glibc-common, and nscd are each
    updated to version 2.5-34.4908.vmw.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2010-3847 and CVE-2010-3856 to the issues
    addressed in this update.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.

    resources.

    VMware would like to thank Nicolas Gregoire and US CERT for
    reporting this issue to us.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-3609 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

VMSA-2011-0008 VMware vCenter Server and vSphere Client security vulnerabilities

    to the network on which the vCenter Server host resides.

    In case vCenter Server is installed on Windows 2008 or
    Windows 2008 R2, the security vulnerability is not present.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the name CVE-2011-0426 to this issue.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================

VMSA-2012-0006 VMware ESXi and ESX address several security issues

      32-bit.
 
      VMware would like to thank Derek Soeder of Ridgeway Internet
      Security, L.L.C. for reporting this issue to us.
   
      The Common Vulnerabilities and Exposures project (cve.mitre.org)
      has assigned the name CVE-2012-1515 to this issue.
 
      Column 4 of the following table lists the action required to
      remediate the vulnerability in each release, if a solution is
      available.

VMSA-2010-0011 VMware Studio 2.1 addresses security vulnerabilities in virtual appliances created with Studio 2.0.

      VAMI features such as using the web interface to set the network
      configuration)
    or
    - recreate the virtual appliance using Studio 2.1.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the name CVE-2010-2667 to this issue.

    VMware would like to thank Claudio Criscione of Secure Network for
    reporting this issue to us.


VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server

    handled uninitialized pointers. An attacker could create a PNG image
    file in such a way, that when loaded by an application linked to
    libpng, it could cause the application to crash or execute arbitrary
    code at the privilege level of the user that runs the application.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-0040 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues

    of the driver.

    VMware would like to thank Nikita Tarakanov for reporting this
    issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-1805 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available. See above for remediation
    details.

VMSA-2008-0019 VMware Hosted products and patches for ESX and ESXi resolve a critical security issue and update bzip2

    write to uncontrolled physical memory.

    VMware would like to thank Andrew Honig of the Department of
    Defense for reporting this issue.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-4917 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2009-0013 VMware Fusion resolves two security issues

    unprivileged user on the host system.

    VMware would like to thank Neil Kettle of Convergent Network
    Solutions for reporting this issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-3281 to this issue.

 b. Kernel denial of service vulnerability

    An integer overflow vulnerability in the vmx86 kernel extension

VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel

 a. Service Console update for COS kernel

    The service console package kernel is updated to version 2.4.21-63.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2008-5029, CVE-2008-5300, CVE-2009-1337,
    CVE-2009-1385, CVE-2009-1895, CVE-2009-2848, CVE-2009-3002, and
    CVE-2009-3547 to the security issues fixed in kernel-2.4.21-63.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)

VMSA-2009-0015 VMware hosted products and ESX patches resolve two security issues

    vulnerability does not affect the host system.

    VMware would like to thank Tavis Ormandy and Julien Tinnes of the
    Google Security Team for reporting this issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-2267 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available. See above for remediation
    details.

VMSA-2008-0018 VMware Hosted products and patches for ESX and ESXi resolve two security issues

    have the ability to run applications.

    VMware would like to thank Derek Soeder for discovering
    this issue and working with us on its remediation.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-4915 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues

    affect the 64-bit versions of Linux guest operating systems.

    VMware would like to thank Derek Soeder for discovering
    this issue and working with us on its remediation.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2008-4279 this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2008-00011 Updated ESX service console packages for Samba and vmnix

 a.  Security Update to Service Console Kernel

   This fix upgrades service console kernel version to 2.4.21-57.EL.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the names CVE-2007-5001, CVE-2007-6151, CVE-2007-6206,
   CVE-2008-0007, CVE-2008-1367, CVE-2008-1375, CVE-2006-4814, and
   CVE-2008-1669 to the security issues fixed in kernel-2.4.21-57.EL.

   VMware         Product   Running  Replace with/

VMSA-2008-0008 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion resolve critical security issues

    have implemented heap protection.

    VMware would like to thank Andrew Honig of the Department of
    Defense for reporting this issue.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-2098 to this issue.

    VMware        Product   Running  Replace with/
    Product       Version   on       Apply Patch
    ============  ========  =======  =================

Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387)

2008-03-18 Vendor fixed issue in trunk/branch revision
2008-04-22 Vendor released 1.3.1
2008-04-22 Advisory published
CVE Information

The Common Vulnerabilities and Exposures (CVE) project has assigned the name 
CVE-2008-1385 to this issue. This is a candidate for inclusion in the CVE 
list (http://cve.mitre.org/), which standardizes names for security problems.
Credits and copyright

This vulnerability was discovered by Hanno Boeck of schokokeks.org webhosting. 

Cross site scripting issues in s9y (CVE-2008-1386, CVE-2008-1387)

2008-03-18 Vendor fixed issue in trunk/branch revision
2008-04-22 Vendor released 1.3.1
2008-04-22 Advisory published
CVE Information

The Common Vulnerabilities and Exposures (CVE) project has assigned the name 
CVE-2008-1385 to this issue. This is a candidate for inclusion in the CVE 
list (http://cve.mitre.org/), which standardizes names for security problems.
Credits and copyright

This vulnerability was discovered by Hanno Boeck of schokokeks.org webhosting. 

VMSA-2008-0002 Low severity security update for VirtualCenter and ESX Server 3.0.2, and ESX 3.0.1

   Tomcat Server Security Update
   This release of VirtualCenter Server updates the Tomcat Server
   package from 5.5.17 to 5.5.25, which addresses multiple security
   issues that existed in the earlier releases of Tomcat Server.

   The Common Vulnerabilities and Exposures project (cve.mitre.org) has
   assigned the names CVE-2005-2090, CVE-2006-7195, and CVE-2007-0450 to
   these issues.

   JRE Security Update
   This release of VirtualCenter Server updates the JRE package from

TSLSA-2007-0028 - multi

  - SECURITY Fix: An error exists in fetchmail which allows
    context-dependent attackers to cause a denial of service (NULL
    dereference and application crash) by refusing certain warning
    messages that are sent over SMTP.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2007-4565 to this issue. 

  quagga < TSL 3.0.5 > < TSL 3.0 > 
  - New Upstream.
  - SECURITY Fix: A vulnerability have been reported in Quagga, caused

TSLSA-2007-0024 - multi

  - SECURITY Fix: Fixes integer overflow in the "file" program, that
    might allow user-assisted attackers to execute arbitrary code via
    a large file that triggers an overflow that bypasses an assert()
    statement. This issue is due to an incorrect patch for CVE-2007-1536.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2007-2799 to this issue.

  gd < TSL 3.0.5 > < TSL 3.0 > < TSL 2.2 >
  - SECURITY Fix: Some vulnerabilities have been reported in the GD
    Graphics Library, where some have unknown impact and others can

VMSA-2010-0016 VMware ESXi and ESX third party updates for Service Console and Likewise components

 a. Service Console OS update for COS kernel

    This patch updates the service console kernel to fix multiple
    security issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2010-0415, CVE-2010-0307,
    CVE-2010-0291, CVE-2010-0622, CVE-2010-1087, CVE-2010-1437, and
    CVE-2010-1088 to these issues.

    Column 4 of the following table lists the action required to

VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console

       socreate(type=2, proto=17) failed with error 55

    VMware would like to thank Jimmy Scott at inet-solutions.be for
    reporting this issue to us.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org) has
    assigned the name CVE-2011-1785 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

VMSA-2012-0004 VMware View privilege escalation and cross-site scripting

    privilege escalation on View virtual desktops.

    VMware would like to thank Tarjei Mandt for reporting theses issues
    to us.
 
    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2012-1509 (XPDM buffer overrun),
    CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null
    pointer dereference) to these issues.
    
    Column 4 of the following table lists the action required to

VMSA-2012-0008 VMware ESX updates to ESX Service Console

 a. ESX third party update for Service Console kernel

    The ESX Service Console Operating System (COS) kernel is updated
    which addresses several security issues in the COS kernel.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the names CVE-2011-3191, CVE-2011-4348 and CVE-2012-0028 to
    these issues.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

Secunia Research: Pulse CMS login.php Arbitrary File Writing Vulnerability

Discovered by Secunia Research.

====================================================================== 
8) References

The Common Vulnerabilities and Exposures (CVE) project has assigned 
CVE-2010-0988 for the vulnerability.

====================================================================== 
9) About Secunia


iDefense Security Advisory 03.09.10: Microsoft Excel MDXSET Record Heap Overflow Vulnerability

on the URLs shown.
http://www.microsoft.com/technet/security/bulletin/MS10-017.mspx

VII. CVE INFORMATION

The Common Vulnerabilities and Exposures (CVE) project has assigned the
name CVE-2010-0261 to this issue. This is a candidate for inclusion in
the CVE list (http://cve.mitre.org/), which standardizes names for
security problems.

VIII. DISCLOSURE TIMELINE

VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues

    VMware would like to thank Daniel Grzelak and Alex Kouzemtchenko of
    stratsec (www.stratsec.net) for finding and reporting this issue.
    VMware would also like to thank Ben Allums of WebWorks.com for working
    on the remediation of this issue with us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the name CVE-2009-3731 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


Secunia Research: Adobe Shockwave Player 3D Model Buffer Overflow

Discovered by Alin Rad Pop, Secunia Research.

====================================================================== 
8) References

The Common Vulnerabilities and Exposures (CVE) project has assigned 
CVE-2009-4002 for the vulnerability.

====================================================================== 
9) About Secunia


<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!