New User, Welcome!     Login

Next Page >>

The Common Vulnerabilities and Exposures

VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

 a. JRE Security Update

    JRE update to version 1.5.0_20, which addresses multiple security
    issues that existed in earlier releases of JRE.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the following names to the security issues fixed in
    JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
    CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099,
    CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103,
    CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107.

VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues

          reboot of the guest system.

    VMware would like to thank iDefense and Stephen Fewer of Harmony
    Security for reporting this issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2007-5671 to this issue.

    VMware        Product   Running  Replace with/
    Product       Version   on       Apply Patch
    ============  ========  =======  =================

VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

    issues that exist in the earlier releases of Microsoft SQL Express.

    Customers using other database solutions need not update for
    these issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2008-5416, CVE-2008-0085, CVE-2008-0086,
    CVE-2008-0107 and CVE-2008-0106 to the issues addressed in MS SQL
    Express Service Pack 3.

    Column 4 of the following table lists the action required to

VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues

~     VMware would like to thank CORE Security Technologies for
~     working with us on this issue.  This addresses advisory
~     CORE-2007-0930.

~     The Common Vulnerabilities and Exposures project (cve.mitre.org)
~     has assigned the name CVE-2008-0923 to this issue.

~     Hosted products
~     ---------------
~     VMware Workstation 6.0 upgrade to version 6.0.3 (Build# 80004)

VMSA-2011-0013 VMware third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

 a. ESX third party update for Service Console openssl RPM

    The Service Console openssl RPM is updated to
    openssl-0.9.8e.12.el5_5.7 resolving two security issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2008-7270 and CVE-2010-4180 to these
    issues.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim

    OpenSSL 0.9.7a-33.24 and earlier does not properly check the return
    value from the EVP_VerifyFinal function, which could allow a remote
    attacker to bypass validation of the certificate chain via a
    malformed SSL/TLS signature for DSA and ECDSA keys.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-5077 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues

    virtual machines on that host.

    VMware would like to thank Andrew Honig of the Department of
    Defense for reporting this issue.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2008-4916 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console

    The ESX Service Console Operating System (COS) kernel is updated to
    kernel-2.6.18-274.3.1.el5 to fix multiple security issues in the
    COS kernel.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the names CVE-2011-0726, CVE-2011-1078, CVE-2011-1079,
    CVE-2011-1080, CVE-2011-1093, CVE-2011-1163, CVE-2011-1166,
    CVE-2011-1170, CVE-2011-1171, CVE-2011-1172, CVE-2011-1494,
    CVE-2011-1495, CVE-2011-1577, CVE-2011-1763, CVE-2010-4649,
    CVE-2011-0695, CVE-2011-0711, CVE-2011-1044, CVE-2011-1182,

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS
    Security (http://www.acrossecurity.com) for reporting this issue
    to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-1141 to this issue.

    Steps needed to remediate this vulnerability:

    Guest systems on VMware Workstation, Player, ACE, Server, Fusion

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues

    VMware would like to thank Jure Skofic and Mitja Kolsek of ACROS
    Security (http://www.acrossecurity.com) for reporting this issue
    to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-1141 to this issue.

    Steps needed to remediate this vulnerability:

    Guest systems on VMware Workstation, Player, ACE, Server, Fusion

VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates

~        This patch fixes a flaw in how the aacraid SCSI driver checked
~        IOCTL command permissions.  This flaw might allow a local user
~        on the service console to cause a denial of service or gain
~        privileges. Thanks to Adaptec for reporting this issue.

~        The Common Vulnerabilities and Exposures project (cve.mitre.org)
~        has assigned the name CVE-2007-4308 to this issue.

~        ESX Server 3.0.2 ESX-1003362
~        http://download3.vmware.com/software/vi/ESX-1003362.tgz
~        md5sum: f828e7c1c00c2b32ebd4f14f92febe16

VMSA-2008-0001 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages

   Alexander Sotirov from VMware Security Research discovered a
   buffer overflow vulnerability in the OpenPegasus Management server.
   This flaw could be exploited by a malicious remote user on the
   service console network to gain root access to the service console.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2007-5360 to this issue.

   RPM Updated: pegasus-2.5-552927
   VM Shutdown: No
   Host Reboot: No

UPDATED VMSA-2008-0001.1 Moderate OpenPegasus PAM Authentication Buffer Overflow and updated service console packages

   Alexander Sotirov from VMware Security Research discovered a
   buffer overflow vulnerability in the OpenPegasus Management server.
   This flaw could be exploited by a malicious remote user on the
   service console network to gain root access to the service console.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2007-5360 to this issue.

   RPM Updated: pegasus-2.5-552927
   VM Shutdown: No
   Host Reboot: No

TSLSA-2007-0026 - multi

    enabled, a remote attacker could send a carefully crafted request
    that would cause the Apache child process handling that request to
    crash. This could lead to a denial of service if using a threaded
    Multi-Processing Module.

    The Common Vulnerabilities and Exposures project has assigned the
    names CVE-2006-5752, CVE-2007-3304 and CVE-2007-1863 to these issues.

  clamav < TSL 3.0.5 > < TSL 3.0 > < TSL 2.2 >
  - SECURITY Fix: Some vulnerabilities have been reported in ClamAV,
    which can potentially be exploited by malicious people to cause a

VMSA-2010-0013

 a. Service Console update for cpio

    The service console package cpio is updated to version 2.5-6.RHEL3.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2005-4268 and CVE-2010-0624 to the issues
    addressed in this update.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2010-0013 VMware ESX third party updates for Service Console

 a. Service Console update for cpio

    The service console package cpio is updated to version 2.5-6.RHEL3.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2005-4268 and CVE-2010-0624 to the issues
    addressed in this update.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is

VMSA-2010-0015 VMware ESX third party updates for Service Console

 a. Service Console update for NSS_db

    The service console package NSS_db is updated to version
    nss_db-2.2-35.4.el5_5.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-0826 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

VMSA-2010-0005 VMware products address vulnerabilities in WebAccess

         chkconfig vmware-webAccess off
      
    VMware would like to thank David Byrne and Tom Leavey of Trustwave's
    SpiderLabs for reporting this issue to us.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2009-2277 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2010-0009 ESXi ntp and ESX Service Console third party updates

 a. Service Console update for COS kernel

    Updated COS package "kernel" addresses the security issues that are
    fixed through versions 2.6.18-164.11.1.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2009-2695, CVE-2009-2908, CVE-2009-3228,
    CVE-2009-3286, CVE-2009-3547, CVE-2009-3613 to the security issues
    fixed in kernel 2.6.18-164.6.1

    The Common Vulnerabilities and Exposures project (cve.mitre.org)

Re: iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration Server login.php Command Injection Vulnerability

iDefense Security Advisory 01.13.09: Oracle Secure Backup Administration 
Server login.php Command Injection Vulnerability
http://archives.neohapsis.com/archives/bugtraq/2009-01/0111.html
The vulnerability is in a function of common.php which is called from the 
login.php page.
The Common Vulnerabilities and Exposures (CVE) project has assigned the 
name CVE-2008-5449 to this issue.

Oracle Secure Backup Administration Server login.php Command Injection 
Vulnerability
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=769

VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

      actions.

      VMware would like to thank Julien Bachmann, Shennan Wang, Shinnai,
      and Michal Bucko for reporting these issues to us.

      The Common Vulnerabilities and Exposures Project (cve.mitre.org)
      has assigned the names CVE-2008-3691, CVE-2008-3692,
      CVE-2008-3693, CVE-2008-3694, CVE-2008-3695, CVE-2007-5438, and
      CVE-2008-3696 to the security issues with VMware ActiveX controls.

      VMware         Product   Running  Replace with/

VMSA-2010-0018 VMware hosted products and ESX patches resolve multiple security issues

    the host to elevate their privileges.

    VMware Workstation and Player running on Microsoft Windows are not
    affected.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-4295 to this issue.

    VMware would like to thank Dan Rosenberg for reporting this issue.

    The following table lists what action remediates the vulnerability

VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console

 a. ESX third party update for Service Console kernel

    This update takes the console OS kernel package to
    kernel-2.6.18-238.9.1 which resolves multiple security issues.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the names CVE-2010-1083, CVE-2010-2492, CVE-2010-2798,
    CVE-2010-2938, CVE-2010-2942, CVE-2010-2943, CVE-2010-3015,
    CVE-2010-3066, CVE-2010-3067, CVE-2010-3078, CVE-2010-3086,
    CVE-2010-3296, CVE-2010-3432, CVE-2010-3442, CVE-2010-3477,
    CVE-2010-3699, CVE-2010-3858, CVE-2010-3859, CVE-2010-3865,

VMSA-2010-0002 VMware vCenter update release addresses multiple security issues in Java JRE

  a. Java JRE Security Update

    JRE update to version 1.5.0_22, which addresses multiple security
    issues that existed in earlier releases of JRE.

    The Common Vulnerabilities and Exposures project (cve.mitre.org) has
    assigned the following names to the security issues fixed in
    JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
    CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099,
    CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103,
    CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107.

VMSA-2010-0004 ESX Service Console and vMA third party updates

    display request (direct or via a custom application), leading to a
    denial of service (application crash) or, potentially, arbitrary
    code execution with the privileges of the user running the
    application using the newt library.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-2905 to this issue.

    The following table lists what action remediates the vulnerability
    (column 4) if a solution is available.


VMSA-2009-0014 VMware ESX patches for DHCP, Service Console kernel, and JRE resolve multiple security issues

    A stack-based buffer overflow in the script_write_params method in
    ISC DHCP dhclient allows remote DHCP servers to execute arbitrary
    code via a crafted subnet-mask option.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-0692 to this issue.

    An insecure temporary file use flaw was discovered in the DHCP
    daemon's init script ("/etc/init.d/dhcpd"). A local attacker could
    use this flaw to overwrite an arbitrary file with the output of the

VMSA-2008-0013 Updated ESX packages for OpenSSL, net-snmp, perl

   a. OpenSSL Binaries Updated

   This fix updates the third party OpenSSL library.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the names CVE-2007-3108 and CVE-2007-5135 to the issues
   addressed by this update.
 
   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch

VMSA-2008-0007 Moderate Updated Service Console packages pcre, net-snmp, and OpenPegasus

~   malicious regular expression, it may have been possible to run
~   arbitrary code as the user running the application.

~   VMware would like to thank Ludwig Nussel for reporting these issues.

~   The Common Vulnerabilities and Exposures project (cve.mitre.org) has
~   assigned the names CVE-2006-7228 and CVE-2007-1660 to these issues.

~   RPM Updated:
~   pcre-3.9-10.4.i386.rpm


VMSA-2010-0014 VMware Workstation, Player, and ACE address several security issues

    Player 3.x is being installed. Installed versions of Workstation and
    Player are not affected. The security issue is no longer present in
    the installer of the new versions of Workstation 7.x and Player 3.x
    (see table below for the version numbers).

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-3277 to this issue.

    VMware would like to thank Alexander Trofimov and Marc Esher for
    independently reporting this issue to VMware.


VMSA-2010-0019 VMware ESX third party updates for Service Console

 a. Service Console update for samba

    The service console package samba is updated to version
    3.0.9-1.3E.18.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the name CVE-2010-3069 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.  

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!