Skip to main content

VMware ESX Service Console Multiple Vulnerabilities

Last Update Date: 28 Jan 2011 Release Date: 8 Dec 2010 4709 Views

RISK: Medium Risk

Multiple vulnerabilities have been identified in VMware ESX, which could be exploited by attackers to bypass security restrictions, disclose or manipulate information, cause a denial of service or execute arbitrary code. These issues are caused by errors in samba, bzip2 and OpenSSL.


Impact

  • Denial of Service
  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • VMware ESX version 3.5 and prior
  • VMware ESX version 3.0.3 and prior

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

VMware ESX 3.5:

  • Apply patches ESX350-201012408-SG, ESX350-201012409-SG, and ESX350-201012401-SG

VMware ESX version 3.0.3:

  • Patches are pending


Vulnerability Identifier


Source


Related Link