Skip to main content

VMware ESX Server Multiple Vulnerabilities

Last Update Date: 19 Nov 2012 10:44 Release Date: 19 Nov 2012 3906 Views

RISK: Medium Risk

TYPE: Operating Systems - VM Ware

TYPE: VM Ware

Multiple vulnerabilities have been identified in VMware ESX Server, which can be exploited by malicious, local users to potentially disclose sensitive information and by malicious people to disclose potentially sensitive information, conduct spoofing and cross-site scripting attacks, and cause a DoS (Denial of Service).

  1. An error within the vSphere API can be exploited to cause a crash.
  2. Some vulnerabilities exist in the bundled vulnerable version of bind.
  3. Some vulnerabilities exist in the bundled vulnerable version of python.
  4. Some vulnerabilities exist in the bundled vulnerable version of expat.
  5. A vulnerability exists in the bundled vulnerable version of nspr and nss.

Impact

  • Cross-Site Scripting
  • Denial of Service
  • Information Disclosure
  • Spoofing

System / Technologies affected

  • VMware ESX Server 4.x

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • Apply patches

Vulnerability Identifier


Source


Related Link