New User, Welcome!     Login

Next Page >>

hosted

VMSA-2010-0004 ESX Service Console and vMA third party updates

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201002406-SG
    ESX            3.5       ESX      not affected

VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

    Update Manager 4.1       Windows  Update 1
    Update Manager 4.0       Windows  affected, patch pending
    Update Manager 1.0       Windows  affected, no patch planned

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            any       ESX      not affected


VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    vCenter        any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           4.0       ESXi     ESXi400-200911201-UG
    ESXi           3.5       ESXi     affected, patch pending

    ESX            4.0       ESX      not affected

VMSA-2010-0009 ESXi ntp and ESX Service Console third party updates

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005401-SG
    ESX            3.5       ESX      not applicable

VMSA-2008-0005 Updated VMware Workstation, VMware Player, VMware Server, VMware ACE, and VMware Fusion resolve critical security issues

- -------------------------------------------------------------------

1. Summary:

~   Several critical security vulnerabilities have been addressed
~   in the newest releases of VMware's hosted product line.

2. Relevant releases:

~   VMware Workstation 6.0.2 and earlier
~   VMware Workstation 5.5.4 and earlier

VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    vCenter        any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      ESX410-201201401-SG
    ESX            4.0       ESX      patch pending

Hosting Controller - Multiple Security Bugs (Extremely Critical)

Title: Multiple Security Bugs In Hosting Controller
Critical: Extremely critical
Impact: Full system administrator access
Vendor: Hosting Controller
Version: 6.1 Hot fix <= 3.3
Vendor URL: www.hostingcontroller.com
Solution: N/A From company - There is temporary solution in this report
Exploit: Available
Release Date: 2007 - December
Credit: www.BugReport.ir

VMSA-2011-0013 VMware third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

    VMware      Product     Running     Replace with/
    Product     Version     on          Apply Patch
    =========   ========    =======     =================
    vCenter     any         Windows     not affected

    hosted*     any         any         not affected

    ESXi        any         any         not affected

    ESX         4.1         ESX         ESX410-201110204-SG
    ESX         4.0         ESX         patch pending

VMSA-2008-0009 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Fusion, VMware Server, VMware VIX API, VMware ESX, VMware ESXi resolve critical security issues

- -------------------------------------------------------------------

1. Summary:

   Several critical security vulnerabilities have been addressed
   in patches in ESX and in the newest releases of VMware's hosted
   product line.

2. Relevant releases:

   VMware Workstation 6.0.3 and earlier,

VMSA-2010-0013

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      affected, patch pending
    ESX            4.0       ESX      affected, patch pending

VMSA-2010-0013 VMware ESX third party updates for Service Console

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      affected, patch pending
    ESX            4.0       ESX      affected, patch pending

VMSA-2010-0015 VMware ESX third party updates for Service Console

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      affected, patch pending
    ESX            4.0       ESX      ESX400-201009407-SG

VMSA-2007-0006 Critical security updates for all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE, and VMware Player

                   CVE-2006-3619 CVE-2006-4146
- - -------------------------------------------------------------------

1. Summary:

Updated versions of all supported hosted products and all ESX 2x
products and patches for ESX 30x address critical security updates.

Service Console security updates for samba, bind, krb5, vixie-cron,
shadow-utils, openldap, pam, gcc, and gdb packages.


CFP: ISOI 7 - Sept 17, 18 - San Diego

The 7th ISOI (Internet Security Operations and Intelligence) will take
place on September 17th and 18th in San Diego, California.

ISOI 7 is kindly hosted by Websense and ESET. The evening reception is
graciously hosted by Facebook.

An early draft agenda can be found here: http://isotf.org/isoi7.html

While attendance is very limited as explained below, it is free of charge.


VMSA-2008-0016 VMware Hosted products, VirtualCenter Update 3 and patches for ESX and ESXi resolve multiple security issues

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2008-0016
Synopsis:          VMware Hosted products, VirtualCenter Update 3 and
patches for ESX and ESXi resolve multiple security issues
Issue date:        2008-10-03
Updated on:        2008-10-03 (initial release of advisory)
CVE numbers:       CVE-2008-4279 CVE-2008-4278 CVE-2008-3103
                   CVE-2008-3104 CVE-2008-3105 CVE-2008-3106

VMSA-2011-0004 VMware ESX/ESXi SLPD denial of service vulnerability and ESX third party updates for Service Console packages bind, pam, and rpm.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    vCenter        any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           4.1       ESXi     ESXi410-201101201-SG
    ESXi           4.0       ESXi     ESXi400-201103401-SG
    ESXi           3.5       ESXi     not applicable


VMSA-2011-0012 VMware ESXi and ESX updates to third party libraries and ESX Service Console

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    vCenter        any       Windows  not affected
    
    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            5.0       ESX      not affected
    ESX            4.1       ESX      patch pending

VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

      VMware ESX 3.0.1 without patches ESX-1005108, ESX-1005112,
                                       ESX-1005111, ESX-1004823,
                                       ESX-1005117.

      NOTE: Hosted products VMware Workstation 5.x, VMware Player 1.x,
            and VMware ACE 1.x will reach end of general support
            2008-11-09. Customers should plan to upgrade to the latest
            version of their respective products.

            Extended support (Security and Bug fixes) for ESX 3.0.2 ends

Re: Apache directory traversal on shared hosting environment.

This is cPanel's full response to David Collins:

> Hello and thank you again for reporting this security issue to  
> cPanel. We appreciate your interest in helping secure the shared  
> hosting environment.
>
> cPanel attempts to deliver a default configuration that suits the  
> majority of our customers. cPanel makes every attempt to provide  
> straight forward interfaces that allow server administrators to  
> configure their hosting platform to serve the needs of their end  

Cisco Security Advisory: Multiple Cisco WebEx WRF Player Vulnerabilities

on the system of a targeted user.

The Cisco WebEx WRF Player is an application that is used to play back
WebEx meeting recordings that have been recorded on the computer of an
on-line meeting attendee. The WRF Player can be automatically installed
when the user accesses a WRF file that is hosted on a WebEx server. The
WRF Player can also be manually installed for offline playback after
downloading the application from www.webex.com.

If the WRF Player was automatically installed, the WebEx WRF Player
will be automatically upgraded to the latest, non-vulnerable version

VMSA-2009-0005 VMware Hosted products, VI Client and patches for ESX and ESXi resolve multiple security issues

- ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2009-0005
Synopsis:          VMware Hosted products, VI Client and patches for ESX
                   and ESXi resolve multiple security issues
Issue date:        2009-04-03
Updated on:        2009-04-03 (initial release of advisory)
CVE numbers:       CVE-2008-4916 CVE-2008-3761 CVE-2009-1146
                   CVE-2009-1147 CVE-2009-0909 CVE-2009-0910

VMSA-2008-0013 Updated ESX packages for OpenSSL, net-snmp, perl

   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch
   =============  ========  =======  =================
   VirtualCenter  any       Windows  affected, patch pending

   hosted *       any       any      for patch info see VMSA-2008-0005
 
   ESXi           3.5       ESXi     affected, patch pending

   ESX            3.5       ESX      for patch info see VMSA-2008-0001
   ESX            3.0.3     ESX      not affected

VMSA-2012-0005 VMware vCenter Server, Orchestrator, Update Manager, vShield, vSphere Client, ESXi and ESX address several security issues

        Update Manager 5.0      Windows     Update Manager 5.0 Update 1
        Update Manager 4.1      Windows     not applicable **
        Update Manager 4.0      Windows     not applicable **

        hosted *       any      any         not affected

        ESXi           any      ESXi        not applicable

        ESX            4.1      ESX         patch pending
        ESX            4.0      ESX         not applicable **

VMSA-2009-0004 ESX Service Console updates for openssl, bind, and vim

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           3.5       ESXi     not affected

    ESX            3.5       ESX      affected, patch pending
    ESX            3.0.3     ESX      ESX303-200903406-SG

VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not applicable

    ESX            4.1       ESX      affected, patch pending
    ESX            4.0       ESX      ESX400-201101405-SG

VMSA-2010-0019 VMware ESX third party updates for Service Console

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.1       ESX      not applicable
    ESX            4.0       ESX      not applicable

VMSA-2009-0001 ESX patches address an issue loading corrupt virtual disks and update Service Console packages

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           3.5       ESXi     ESXe350-200901401-I-SG

    ESX            3.5       ESX      ESX350-200901401-SG
    ESX            3.0.3     ESX      not affected

VMSA-2009-0009 ESX Service Console updates for udev, sudo, and curl

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-200906411-SG
    ESX            3.5       ESX      not affected

VMSA-2008-0019 VMware Hosted products and patches for ESX and ESXi resolve a critical security issue and update bzip2

- -------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2008-0019
Synopsis:          VMware Hosted products and patches for ESX and ESXi
                   resolve a critical security issue and update bzip2
Issue date:        2008-12-02
Updated on:        2008-12-02 (initial release of advisory)
CVE numbers:       CVE-2008-4917 CVE-2008-1372
- -------------------------------------------------------------------------

Cisco Security Advisory: Multiple Cisco WebEx Player Vulnerabilities

user.

The Cisco WebEx Players are applications that are used to play back
WebEx meeting recordings that have been recorded on the computer of
an on-line meeting attendee. The players can be automatically
installed when the user accesses a recording file that is hosted on a
WebEx server. The player can also be manually installed for offline
playback after downloading the application from www.webex.com

If the WebEx recording player was automatically installed, it will be
automatically upgraded to the latest, non-vulnerable version when

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!