New User, Welcome!     Login

Next Page >>

The Common

VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

 a. JRE Security Update

    JRE update to version 1.5.0_20, which addresses multiple security
    issues that existed in earlier releases of JRE.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the following names to the security issues fixed in
    JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
    CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099,
    CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103,
    CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107.

VMSA-2010-0009 ESXi ntp and ESX Service Console third party updates

 a. Service Console update for COS kernel

    Updated COS package "kernel" addresses the security issues that are
    fixed through versions 2.6.18-164.11.1.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2009-2695, CVE-2009-2908, CVE-2009-3228,
    CVE-2009-3286, CVE-2009-3547, CVE-2009-3613 to the security issues
    fixed in kernel 2.6.18-164.6.1

    The Common Vulnerabilities and Exposures project (cve.mitre.org)

VMSA-2010-0004 ESX Service Console and vMA third party updates

    display request (direct or via a custom application), leading to a
    denial of service (application crash) or, potentially, arbitrary
    code execution with the privileges of the user running the
    application using the newt library.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-2905 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues

          reboot of the guest system.

    VMware would like to thank iDefense and Stephen Fewer of Harmony
    Security for reporting this issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2007-5671 to this issue.

    VMware        Product   Running  Replace with/
    Product       Version   on       Apply Patch
    ============  ========  =======  =================

VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

    issues that exist in the earlier releases of Microsoft SQL Express.

    Customers using other database solutions need not update for
    these issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2008-5416, CVE-2008-0085, CVE-2008-0086,
    CVE-2008-0107 and CVE-2008-0106 to the issues addressed in MS SQL
    Express Service Pack 3.

    Column 4 of the following table lists the action required to

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS
    Security (http://www.acrossecurity.com) for reporting this issue
    to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-1141 to this issue.

    Steps needed to remediate this vulnerability:

    Guest systems on VMware Workstation, Player, ACE, Server, Fusion

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS
    Security (http://www.acrossecurity.com) for reporting this issue
    to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-1141 to this issue.

    Steps needed to remediate this vulnerability:

    Guest systems on VMware Workstation, Player, ACE, Server, Fusion

VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues

    virtual machines on that host.

    VMware would like to thank Andrew Honig of the Department of
    Defense for reporting this issue.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-4916 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

      actions.

      VMware would like to thank Julien Bachmann, Shennan Wang, Shinnai,
      and Michal Bucko for reporting these issues to us.

      The Common Vulnerabilities and Exposures Project (cve.mitre.org)
      has assigned the names CVE-2008-3691, CVE-2008-3692,
      CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, CVE-2007-5438, and
      CVE-2008-3696 to the security issues with VMware ActiveX controls.

      VMware         Product   Running  Replace with/

VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues

~     VMware would like to thank CORE Security Technologies for
~     working with us on this issue.  This addresses advisory
~     CORE-2007-0930.

~     The Common Vulnerabilities and Exposures project (cve.mitre.org)
~     has assigned the name CVE-2008-0923 to this issue.

~     Hosted products
~     ---------------
~     VMware Workstation 6.0 upgrade to version 6.0.3 (Build# 80004)

VMSA-2011-0013 VMware third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

 a. ESX third party update for Service Console openssl RPM

    The Service Console openssl RPM is updated to
    openssl-0.9.8e.12.el5_5.7 resolving two security issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2008-7270 and CVE-2010-4180 to these
    issues.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim

    OpenSSL 0.9.7a-33.24 and earlier does not properly check the return
    value from the EVP_VerifyFinal function, which could allow a remote
    attacker to bypass validation of the certificate chain via a
    malformed SSL/TLS signature for DSA and ECDSA keys.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-5077 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console

    The ESX Service Console Operating System (COS) kernel is updated to
    kernel-2.6.18-274.3.1.el5 to fix multiple security issues in the
    COS kernel.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the names CVE-2011-0726, CVE-2011-1078, CVE-2011-1079,
    CVE-2011-1080, CVE-2011-1093, CVE-2011-1163, CVE-2011-1166,
    CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-1494,
    CVE-2011-1495, CVE-2011-1577, CVE-2011-1763, CVE-2010-4649,
    CVE-2011-0695, CVE-2011-0711, CVE-2011-1044, CVE-2011-1182,

VMSA-2012-0005 VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, ESXi and ESX address several security issues

      Systems.

      VMware would like to thank Tarjei Mandt for reporting theses
      issues to us.

      The Common Vulnerabilities and Exposures project (cve.mitre.org)
      has assigned the names CVE-2012-1509 (XPDM buffer overrun),
      CVE-2012-1510 (WDDM buffer overrun) and CVE-2012-1508 (XPDM null
      pointer dereference) to these issues.

      Note: CVE-2012-1509 doesn't affect ESXi and ESX.

VMSA-2009-0014 VMware ESX patches for DHCP, Service Console kernel, and JRE resolve multiple security issues

    A stack-based buffer overflow in the script_write_params method in
    ISC DHCP dhclient allows remote DHCP servers to execute arbitrary
    code via a crafted subnet-mask option.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-0692 to this issue.

    An insecure temporary file use flaw was discovered in the DHCP
    daemon's init script ("/etc/init.d/dhcpd"). A local attacker could
    use this flaw to overwrite an arbitrary file with the output of the

VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates

~        This patch fixes a flaw in how the aacraid SCSI driver checked
~        IOCTL command permissions.  This flaw might allow a local user
~        on the service console to cause a denial of service or gain
~        privileges. Thanks to Adaptec for reporting this issue.

~        The Common Vulnerabilities and Exposures project (cve.mitre.org)
~        has assigned the name CVE-2007-4308 to this issue.

~        ESX Server 3.0.2 ESX-1003362
~        http://download3.vmware.com/software/vi/ESX-1003362.tgz
~        md5sum: f828e7c1c00c2b32ebd4f14f92febe16

VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages

   Alexander Sotirov from VMware Security Research discovered a
   buffer overflow vulnerability in the OpenPegasus Management server.
   This flaw could be exploited by a malicious remote user on the
   service console network to gain root access to the service console.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2007-5360 to this issue.

   RPM Updated: pegasus-2.5-552927
   VM Shutdown: No
   Host Reboot: No

UPDATED VMSA-2008-0001.1 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages

   Alexander Sotirov from VMware Security Research discovered a
   buffer overflow vulnerability in the OpenPegasus Management server.
   This flaw could be exploited by a malicious remote user on the
   service console network to gain root access to the service console.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2007-5360 to this issue.

   RPM Updated: pegasus-2.5-552927
   VM Shutdown: No
   Host Reboot: No

TSLSA-2007-0026 - multi

    enabled, a remote attacker could send a carefully crafted request
    that would cause the Apache child process handling that request to
    crash. This could lead to a denial of service if using a threaded
    Multi-Processing Module.

    The Common Vulnerabilities and Exposures project has assigned the
    names CVE-2006-5752, CVE-2007-3304 and CVE-2007-1863 to these issues.

  clamav < TSL 3.0.5 > < TSL 3.0 > < TSL 2.2 >
  - SECURITY Fix: Some vulnerabilities have been reported in ClamAV,
    which can potentially be exploited by malicious people to cause a

VMSA-2010-0013

 a. Service Console update for cpio

    The service console package cpio is updated to version 2.5-6.RHEL3.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2005-4268 and CVE-2010-0624 to the issues
    addressed in this update.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2010-0013 VMware ESX third party updates for Service Console

 a. Service Console update for cpio

    The service console package cpio is updated to version 2.5-6.RHEL3.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2005-4268 and CVE-2010-0624 to the issues
    addressed in this update.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2010-0015 VMware ESX third party updates for Service Console

 a. Service Console update for NSS_db

    The service console package NSS_db is updated to version
    nss_db-2.2-35.4.el5_5.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-0826 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

VMSA-2012-0009 VMware Workstation, Player, ESXi and ESX patches address critical security issues

    Mitigation
    - Do not allow untrusted users access to your virtual machines.
      Root or Administrator level permissions are not required to
      exploit this issue.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2012-1516 to this issue.

    VMware would like to thank Derek Soeder of Ridgeway Internet
    Security, L.L.C. for reporting this issue to us.


[MATTA-2011-003] Restorepoint Remote root command execution vulnerability - CVE-2011-4201 CVE-2011-4202

The 3.2 evaluation image of Restorepoint is vulnerable to a remote command
 execution vulnerability in the remote_support.cgi script prior to license
 activation. By supplying a semi colon followed by a unix shell command to
 the pid1 or pid2 parameters in conjunction with the stop_remote_support
 parameter, an unauthenticated remote attacker can execute commands on the
 Restorepoint appliance with the privileges of the www user. The Common
 Vulnerabilities and Exposures (CVE) project has assigned the name
 CVE-2011-4201 to this issue. This is a candidate for inclusion in
 the CVE list (http://cve.mitre.org), which standardizes names for security
 problems.


VMSA-2010-0005 VMware products address vulnerabilities in WebAccess

         chkconfig vmware-webAccess off
      
    VMware would like to thank David Byrne and Tom Leavey of Trustwave's
    SpiderLabs for reporting this issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-2277 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2009-0001 ESX patches address an issue loading corrupt virtual disks and update Service Console packages

    A corrupt VMDK delta disk, or virtual machine would have to be loaded
    by an administrator.

    VMware would like to thank Craig Marshall for reporting this issue.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2008-4914 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


Re: iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Server login.php Command Injection Vulnerability

iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration 
Server login.php Command Injection Vulnerability
http://archives.neohapsis.com/archives/bugtraq/2009-01/0111.html
The vulnerability is in a function of common.php which is called from the 
login.php page.
The Common Vulnerabilities and Exposures (CVE) project has assigned the 
name CVE-2008-5449 to this issue.

Oracle Secure Backup Administration Server login.php Command Injection 
Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=769

VMSA-2010-0018 VMware hosted products and ESX patches resolve multiple security issues

    the host to elevate their privileges.

    VMware Workstation and Player running on Microsoft Windows are not
    affected.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-4295 to this issue.

    VMware would like to thank Dan Rosenberg for reporting this issue.

    The following table lists what action remediates the vulnerability

VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.

    resources.

    VMware would like to thank Nicolas Gregoire and US CERT for
    reporting this issue to us.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-3609 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console

 a. ESX third party update for Service Console kernel

    This update takes the console OS kernel package to
    kernel-2.6.18-238.9.1 which resolves multiple security issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798,
    CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015,
    CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086,
    CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477,
    CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865,

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!