New User, Welcome!     Login

<< Previous Next >>

VMware ESX

VMSA-2010-0015 VMware ESX third party updates for Service Console

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      affected, patch pending
    ESX            4.0       ESX      ESX400-201009407-SG
    ESX            3.5       ESX      not applicable
    ESX            3.0.3     ESX      not applicable

VMSA-2009-0014 VMware ESX patches for DHCP, Service Console kernel, and JRE resolve multiple security issues

    =============  ========  =======  =================
    vCenter        any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      ESX350-200910406-SG
    ESX            3.0.3     ESX      ESX303-200910402-SG
    ESX            2.5.5     ESX      not affected

VMSA-2010-0016 VMware ESXi and ESX third party updates for Service Console and Likewise components

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2010-0016
Synopsis:          VMware ESXi and ESX third party updates for Service
                   Console and Likewise components
Issue date:        2010-11-15
Updated on:        2010-11-15 (initial release of advisory)
CVE numbers:       CVE-2010-0415 CVE-2010-0307 CVE-2010-0291
                   CVE-2010-0622 CVE-2010-1087 CVE-2010-1437

VMSA-2011-0008 VMware vCenter Server and vSphere Client security vulnerabilities

   vCenter Server 4.1 GA
   vCenter Server 4.0 Update 2 and earlier
   VirtualCenter 2.5 Update 6 and earlier

   ESXi 4.1 GA
   ESXi 4.0 without patch ESXi400-201103402-SG

   ESX 4.1 GA
   ESX 4.0 without patch ESX400-201103401-SG


VMSA-2010-0005 VMware products address vulnerabilities in WebAccess

    VirtualCenter  2.5       Windows  Virtual Center 2.5 Update 6
    VirtualCenter  2.0.2     Windows  not being fixed at this time *
 
    hosted **      any       any      not affected    

    ESXi           any       ESXi     not affected
 
    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      ESX350-201003403-SG
    ESX            3.0.3     ESX      not being fixed at this time *
    ESX            2.5.5     ESX      not affected

VMSA-2010-0019 VMware ESX third party updates for Service Console

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      not applicable
    ESX            4.0       ESX      not applicable
    ESX            3.5       ESX      ESX350-201012408-SG
    ESX            3.0.3     ESX      affected, patch pending

VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not applicable

    ESX            4.1       ESX      affected, patch pending
    ESX            4.0       ESX      ESX400-201101405-SG
    ESX            3.5       ESX      not applicable
    ESX            3.0.3     ESX      not applicable

VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            3.5       ESX      affected, patch pending
    ESX            3.0.3     ESX      ESX303-200903406-SG
    ESX            3.0.2     ESX      ESX-1008409
    ESX            2.5.5     ESX      affected, patch pending

VMSA-2009-0010 VMware Hosted products update libpng and Apache HTTP Server

    Server         1.x       any      patch pending

    Fusion         2.x       Mac OS/X not affected
    Fusion         1.x       Mac OS/X not affected

    ESXi           4.0       ESXi     not affected
    ESXi           3.5       ESXi     not affected

    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected

VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-200906411-SG
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected

VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues

    Server         any       any      not affected

    Fusion         any       Mac OS/X not affected

    ESXi           any       ESXi     not affected

    ESX            any       ESX      not affected

 * Note: This only affects the installer, if you have a version of
         Workstation or Player installed you are not vulnerable.

VMSA-2011-0002 Cisco Nexus 1000V VEM updates address denial of service in VMware ESX/ESXi

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2011-0002
Synopsis:          Cisco Nexus 1000V VEM updates address denial of
                   service in VMware ESX/ESXi
Issue date:        2011-02-07
Updated on:        2011-02-07 (initial release of advisory)
CVE numbers:       CVE-2011-0355
- ------------------------------------------------------------------------


VMSA-2008-0013 Updated ESX packages for OpenSSL, net-snmp, perl

   =============  ========  =======  =================
   VirtualCenter  any       Windows  affected, patch pending

   hosted *       any       any      for patch info see VMSA-2008-0005
 
   ESXi           3.5       ESXi     affected, patch pending

   ESX            3.5       ESX      for patch info see VMSA-2008-0001
   ESX            3.0.3     ESX      not affected
   ESX            3.0.2     ESX      affected, patch pending
   ESX            3.0.1     ESX      affected, patch pending

VMSA-2012-0008 VMware ESX updates to ESX Service Console

    =============  ========  =======  =================
    vCenter        any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      ESX410-201204401-SG
    ESX            4.0       ESX      patch pending **
    ESX            3.5       ESX      not applicable


VMware Tools Multiple Vulnerabilities

       AMS         any         any         not affected

       Fusion      3.1.x       OSX         Fusion 3.1.3 or later*

       ESXi        4.1         ESXi        ESXi410-201104402-BG*
       ESXi        4.0         ESXi        ESXi400-201104402-BG*
       ESXi        3.5         ESXi        ESXe350-201105402-T-SG*

       ESX         4.1         ESX         ESX410-201104401-SG*
       ESX         4.0         ESX         ESX400-201104401-SG*

VMSA-2010-0006 ESX Service Console updates for samba and acpid

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201003405-SG
    ESX            3.5       ESX      patch pending
    ESX            3.0.3     ESX      patch pending
    ESX            2.5.5     ESX      patch pending

VMSA-2008-00011 Updated ESX service console packages for Samba and vmnix

   =============  ========  =======  =================
   VirtualCenter  any       Windows  not applicable

   hosted         any       any      not applicable

   ESXi           3.5       ESXi     not applicable

   ESX            3.5       ESX      patch ESX350-200806201-UG
   ESX            3.0.2     ESX      affected, no update planned
   ESX            3.0.1     ESX      affected, no update planned
   ESX            2.5.5     ESX      not applicable

VMSA-2011-0014 VMware vCenter Update Manager fix for Jetty Web server addresses directory traversal vulnerability

    Update Manager 4.1       Windows  Update 2
    Update Manager 4.0       Windows  Update 4
      
    hosted *       any       any      not affected
      
    ESXi           any       ESXi     not affected
      
    ESX            any       ESX      not affected
      
  * hosted products are VMware Workstation, Player, ACE, Fusion.


VMSA-2010-0017 VMware ESX third party update for Service Console kernel

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      ESX410-201011402-SG
    ESX            4.0       ESX      patch pending
    ESX            3.x       ESX      not applicable


VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      not applicable
    ESX            3.5       ESX      ESX350-201006401-SG
    ESX            3.0.3     ESX      affected, no update planned


VMSA-2009-0008 ESX Service Console update for krb5

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            4.0       ESX      affected, patch pending
    ESX            3.5       ESX      ESX350-200906407-SG
    ESX            3.0.3     ESX      affected, patch pending
    ESX            3.0.2     ESX      affected, patch pending

Trustwave's SpiderLabs Security Advisory TWSL2010-002

    VirtualCenter  2.5       Windows  Virtual Center 2.5 Update 6
    VirtualCenter  2.0.2     Windows  not being fixed at this time *

    hosted **      any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      ESX350-201003403-SG
    ESX            3.0.3     ESX      not being fixed at this time *
    ESX            2.5.5     ESX      not affected

VMSA-2010-0001 ESX Service Console updates for nss and nspr

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-200912403-SG
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected

VMSA-2010-0003 ESX Service Console update for net-snmp

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      not affected
    ESX            3.5       ESX      ESX350-201002401-SG
    ESX            3.0.3     ESX      affected, patch pending
    ESX            2.5.5     ESX      not affected

VMSA-2012-0003 VMware VirtualCenter Update and ESX 3.5 patch update JRE

    vCenter        4.0       Windows  patch pending
    VirtualCenter  2.5       Windows  VirtualCenter 2.5 Update 6b
            
    hosted *       any       any      not affected
      
    ESXi           any       ESXi     not affected
      
    ESX            4.1       ESX      not applicable **
    ESX            4.0       ESX      patch pending
    ESX            3.5       ESX      ESX350-201203401-SG


VMSA-2009-0003 ESX 2.5.5 patch 12 updates service console package ed

    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            3.0.2     ESX      not affected
    ESX            2.5.5     ESX      Upgrade Patch 12

[Tool] DoS for OpenSLP (and others)

Hello !

SLP (Service Location Protocol) is defined by RFC 2165 and RFC 2608.
OpenSLP (the reference implementation) and others SLP softwares (like
mSLP) are vulnerable to a denial of service vulnerability (CVE-2010-3609
aka CERT VU#393783). The affected softwares include VMware ESX and ESXi,
Novell eDirectory, several SAN manufacturers, some Linux
distributions, ...

Here's a PoC triggering this vulnerability via either unicast (TCP or
UDP), broadcast and multicast : http://www.agarri.fr/docs/SLPick.py

VMSA-2009-0017 VMware vCenter, ESX patch and vCenter Lab Manager releases address cross-site scripting issues

    ACE            any       any      not affected

    Fusion         any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-200911223-UG
    ESX            3.5       ESX      not affected
    ESX            3.0.3     ESX      not affected
    ESX            2.5.5     ESX      not affected

SFCB vulnerabilities

Vulnerable versions : from 1.3.4 to 1.3.7

[=] Note about VMware products

VMware ESXi 3.5, ESXi 4 and ESX 4 are running by default a modified
version of SFCB (v1.3.3 in ESX 4). However they were tested as non
vulnerable :
- CVE-2010-1937 has been silently patched in WMware products
- CVE-2010-2054 doesn't affect versions lower than 1.3.4
 

VMSA-2011-0006 VMware vmrun utility local privilege escalation

    AMS            any       any      not affected

    Fusion         any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            any       ESX      not affected

   * Refer to VMware Knowledge Base article 1035509 for the updated
     version of vmrun for Workstation 6.5.x.

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!