Vissza a www.andrews.hu-ra

    [guru] VMware biztonsagi frissitesek


    DATE: Tue, 09 Mar 2010 00:56:23 +0100
    Általános javítások:
    --------------------
    A vCenter java javítása számtalan biztonsági hibát orvosol.
    
    
    ESX szervíz konzol javítások:
    -----------------------------
    A net-snmp csomagban levő snmpd daemon egy nullával osztás miatt DoS-olható.
    
    A newt csomag heap buffer overflow hibát tartalmaz.
    
    Az nfs-utils tcp wrapper támogatása nem megfelelő, bizonyos körülmények
    között a /etc/hosts.{allow,deny} állományok ellenőrzése elmaradt.
    
    Több biztonsági hibát is találtak a glib2 csomag base64 kezelésében.
    
    Az openssl csomag DTLS implementációja, illetve a BMPString és
    UniversalString ASN.1 adattípusok megjelenítése DoS-olható.
    
    A bind DNSSEC ellenőrzés nélkül cache-elt válaszokat, ez cache poisoning
    támadást tett lehetővé.
    
    Az expat rutinkönyvtár az XML állomány UTF-8 sztringjeinek ellenőrzése
    buffer overflow hibákat tartalmaz.
    
    Az sshd egy Red Hat specifikus patch-et tartalmaz, ami a ChrootDirectory
    opciójának megadott könyvtár jog ellenőrzésén lazít. A támadó tetszőleges
    felhasználó jogaival kódot futtathat.
    
    Az ntp daemon protokoll kezelése hibás, egy hamisított csomag segítségével
    két daemon ping-pong-ozásra késztethető.
    
    Kihozták a kernel javítását, ami számtalan problémát orvosol.
    
    Javították a kpartx, libvolume-id, device-mapper-multipath, fipscheck,
    dbus, dbus-libs, és ed csomagokat is.
    
    
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - -----------------------------------------------------------------------
                      VMware Security Advisory
    
    Advisory ID:       VMSA-2010-0002
    Synopsis:          VMware vCenter update release addresses multiple
                      security issues in Java JRE
    Issue date:        2010-01-29
    Updated on:        2010-01-29 (initial release of advisory)
    CVE numbers:       --- JRE ---
                      CVE-2009-1093 CVE-2009-1094 CVE-2009-1095
                      CVE-2009-1096 CVE-2009-1097 CVE-2009-1098
                      CVE-2009-1099 CVE-2009-1100 CVE-2009-1101
                      CVE-2009-1102 CVE-2009-1103 CVE-2009-1104
                      CVE-2009-1105 CVE-2009-1106 CVE-2009-1107
                      CVE-2009-2625 CVE-2009-2670 CVE-2009-2671
                      CVE-2009-2672 CVE-2009-2673 CVE-2009-2675
                      CVE-2009-2676 CVE-2009-2716 CVE-2009-2718
                      CVE-2009-2719 CVE-2009-2720 CVE-2009-2721
                      CVE-2009-2722 CVE-2009-2723 CVE-2009-2724
                      CVE-2009-3728 CVE-2009-3729 CVE-2009-3864
                      CVE-2009-3865 CVE-2009-3866 CVE-2009-3867
                      CVE-2009-3868 CVE-2009-3869 CVE-2009-3871
                      CVE-2009-3872 CVE-2009-3873 CVE-2009-3874
                      CVE-2009-3875 CVE-2009-3876 CVE-2009-3877
                      CVE-2009-3879 CVE-2009-3880 CVE-2009-3881
                      CVE-2009-3882 CVE-2009-3883 CVE-2009-3884
    
    CVE-2009-3886 CVE-2009-3885
    - -----------------------------------------------------------------------
    
    1. Summary
    
      Updated Java JRE packages address several security issues.
    
    2. Relevant releases
    
      Virtual Center 2.5 before Update 6
    
    3. Problem Description
    
     a. Java JRE Security Update
    
       JRE update to version 1.5.0_22, which addresses multiple security
       issues that existed in earlier releases of JRE.
    
       The Common Vulnerabilities and Exposures project (cve.mitre.org) has
       assigned the following names to the security issues fixed in
       JRE 1.5.0_18: CVE-2009-1093, CVE-2009-1094, CVE-2009-1095,
       CVE-2009-1096, CVE-2009-1097, CVE-2009-1098, CVE-2009-1099,
       CVE-2009-1100, CVE-2009-1101, CVE-2009-1102, CVE-2009-1103,
       CVE-2009-1104, CVE-2009-1105, CVE-2009-1106, and CVE-2009-1107.
    
       The Common Vulnerabilities and Exposures project (cve.mitre.org) has
       assigned the following names to the security issues fixed in
       JRE 1.5.0_20: CVE-2009-2625, CVE-2009-2670, CVE-2009-2671,
       CVE-2009-2672, CVE-2009-2673, CVE-2009-2675, CVE-2009-2676,
       CVE-2009-2716, CVE-2009-2718, CVE-2009-2719, CVE-2009-2720,
       CVE-2009-2721, CVE-2009-2722, CVE-2009-2723, CVE-2009-2724.
    
       The Common Vulnerabilities and Exposures project (cve.mitre.org) has
       assigned the following names to the security issues fixed in
       JRE 1.5.0_22: CVE-2009-3728, CVE-2009-3729, CVE-2009-3864,
       CVE-2009-3865, CVE-2009-3866, CVE-2009-3867, CVE-2009-3868,
       CVE-2009-3869, CVE-2009-3871, CVE-2009-3872, CVE-2009-3873,
       CVE-2009-3874, CVE-2009-3875, CVE-2009-3876, CVE-2009-3877,
       CVE-2009-3879, CVE-2009-3880, CVE-2009-3881, CVE-2009-3882,
       CVE-2009-3883, CVE-2009-3884, CVE-2009-3886, CVE-2009-3885.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       vCenter        4.0       Windows  affected, patch pending *
       VirtualCenter  2.5       Windows  Update 6
       VirtualCenter  2.0.2     Windows  affected, patch pending
    
       Workstation    any       any      not affected
    
       Player         any       any      not affected
    
       Server         2.0       any      not being fixed at this time
       Server         1.0       any      not affected
    
       ACE            any       any      not affected
    
       Fusion         any       any      not affected
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      affected, patch pending *
       ESX            3.5       ESX      affected, patch pending **
       ESX            3.0.3     ESX      affected, patch pending
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    affected, patch pending
    
     * The JRE version of vCenter 4.0 and ESX 4.0 will be updated in the
       Update 2 release of vCenter 4.0 and ESX 4.0. See VMSA-2009-0016.1
       for the update of JRE in vCenter 4.0 Update 1 and in ESX 4.0
       Update 1.
    
     ** The JRE version of ESX 3.5 will be updated in an upcoming patch
        release. See VMSA-2009-0014.2 for the update of JRE in ESX 3.5
        Patch 18.
    
       Notes: These vulnerabilities can be exploited remotely only if the
              attacker has access to the Service Console network.
    
              Security best practices provided by VMware recommend that the
              Service Console be isolated from the VM network. Please see
              http://www.vmware.com/resources/techresources/726 for more
              information on VMware security best practices.
    
              The currently installed version of JRE depends on your patch
              deployment history.
    
    
    4. Solution
    
      Please review the patch/release notes for your product and version
      and verify the sha1sum or md5sum of your downloaded file.
    
      VMware Virtual Center 2.5 Update 6
      ----------------------------------
      Version       2.5 Update 6
      Build Number  227637
      Release Date  2010/01/29
      Type          Product Binaries
      http://downloads.vmware.com/download/download.do?downloadGroup=VC250U6
    
      VirtualCenter DVD image - English only version
      File size: 854 MB
      File type: .iso
      md5sum: d83b09ac0533a418d5b7f5493dbd3ed3
      sha1sum: 1b969b397a937402b5e9463efc767eff7a980ad0
    
      VirtualCenter as a Zip file - English only version
      File size: 625 MB
      File type: .zip
      md5sum: 760f335ebcd363e0e159b20da923621f
      sha1sum: e400bc1008d1e4c44d204a8135293b8ae305f14e
    
    VMware vCenter Converter BootCD
      VMware Converter Enterprise BootCD for VirtualCenter
      File size: 97 MB
      File type: .zip
      md5sum: e49e0ff0f2563196cc5d4b5c471cd666
    
      VMware vCenter Converter CLI (Linux)
      VMware Converter Enterprise CLI for Linux platform
      File size: 37 MB
      File type: .tar.gz
      md5sum: 30d1f5e58a6cad8dacd988908305bc1c
    
    
    
    5. References
    
      CVE numbers
      --- JRE ---
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1093
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1094
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1095
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1096
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1097
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1098
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1099
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1100
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1101
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1102
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1103
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1104
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1105
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1106
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1107
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2625
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2670
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2671
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2672
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2673
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2675
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2676
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2716
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2718
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2719
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2720
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2721
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2722
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2723
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2724
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3728
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3729
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3864
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3865
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3866
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3867
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3868
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3869
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3871
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3872
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3873
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3874
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3875
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3876
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3877
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3879
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3880
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3881
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3882
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3883
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3884
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3886
    
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3885
    - ------------------------------------------------------------------------
    6. Change log
    
    2010-01-29  VMSA-2010-0002
    Initial security advisory after release of Virtual Center 2.5 Update 6
    on 2010-01-29
    
    - -----------------------------------------------------------------------
    7. Contact
    
    E-mail list for product security notifications and announcements:
    http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce
    
    This Security Advisory is posted to the following lists:
    
     * security-announce at lists.vmware.com
     * bugtraq at securityfocus.com
     * full-disclosure at lists.grok.org.uk
    
    E-mail:  security at vmware.com
    PGP key at: http://kb.vmware.com/kb/1055
    
    VMware Security Center
    http://www.vmware.com/security
    
    VMware security response policy
    http://www.vmware.com/support/policies/security_response.html
    
    General support life cycle policy
    http://www.vmware.com/support/policies/eos.html
    
    VMware Infrastructure support life cycle policy
    http://www.vmware.com/support/policies/eos_vi.html
    
    Copyright 2010 VMware Inc.  All rights reserved.
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP Desktop 9.8.3 (Build 4028)
    Charset: utf-8
    
    wj8DBQFLY9rGS2KysvBH1xkRArbSAJ9VArpROb/WYxDFHVWpxoZvX60t4wCfQVqo
    F4sDVTv0QCg807Ds70VV454=
    =OKeR
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - -------------------------------------------------------------------------
                       VMware Security Advisory
    
    Advisory ID:       VMSA-2010-0003
    Synopsis:          ESX Service Console update for net-snmp
    Issue date:        2010-02-16
    Updated on:        2010-02-16 (initial release of advisory)
    CVE numbers:       CVE-2009-1887
    - -------------------------------------------------------------------------
    
    1. Summary
    
       Update for Service Console package net-snmp
    
    2. Relevant releases
    
       VMware ESX 3.5 without patch ESX350-201002401-SG
    
    3. Problem Description
    
     a. Service Console package net-snmp updated
    
        This patch updates the service console package for net-snmp,
        net-snmp-utils, and net-snmp-libs to version
        net-snmp-5.0.9-2.30E.28. This net-snmp update fixes a divide-by-
        zero flaw in the snmpd daemon. A remote attacker could issue a
        specially crafted GETBULK request that could cause the snmpd daemon
        to fail.
    
        This vulnerability was introduced by an incorrect fix for
        CVE-2008-4309.
    
        The Common Vulnerabilities and Exposures Project (cve.mitre.org) has
        assigned the name CVE-2009-1887 to this issue.
    
        Note: After installing the previous patch for net-snmp
        (ESX350-200901409-SG), running the snmpbulkwalk command with the
        parameter -CnX results in no output, and the snmpd daemon stops.
    
        The following table lists what action remediates the vulnerability
        (column 4) if a solution is available.
    
        VMware         Product   Running  Replace with/
        Product        Version   on       Apply Patch
        =============  ========  =======  =================
        VirtualCenter  any       Windows  not affected
    
        hosted *       any       any      not affected
    
        ESXi           any       ESXi     not affected
    
        ESX            4.0       ESX      not affected
        ESX            3.5       ESX      ESX350-201002401-SG
        ESX            3.0.3     ESX      affected, patch pending
        ESX            2.5.5     ESX      not affected
    
      * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    4. Solution
    
       Please review the patch/release notes for your product and version
       and verify the md5sum of your downloaded file.
    
       ESX 3.5
       -------
       ESX350-201002401-SG
       http://download3.vmware.com/software/vi/ESX350-201002401-SG.zip
       md5sum: a91428cb6bc2da794f581aefd5eef010
       http://kb.vmware.com/kb/1017660
    
    5. References
    
       CVE numbers
       http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1887
    
    - -------------------------------------------------------------------------
    6. Change log
    
    2010-02-16  VMSA-2010-0003
    Initial security advisory after release of patches for ESX 3.5
    on 2010-02-16.
    
    - ------------------------------------------------------------------------
    7. Contact
    
    E-mail list for product security notifications and announcements:
    http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce
    
    This Security Advisory is posted to the following lists:
    
      * security-announce at lists.vmware.com
      * bugtraq at securityfocus.com
      * full-disclosure at lists.grok.org.uk
    
    E-mail:  security at vmware.com
    PGP key at: http://kb.vmware.com/kb/1055
    
    VMware Security Center
    http://www.vmware.com/security
    
    VMware security response policy
    http://www.vmware.com/support/policies/security_response.html
    
    General support life cycle policy
    http://www.vmware.com/support/policies/eos.html
    
    VMware Infrastructure support life cycle policy
    http://www.vmware.com/support/policies/eos_vi.html
    
    Copyright 2010 VMware Inc.  All rights reserved.
    -----BEGIN PGP SIGNATURE-----
    Version: GnuPG v2.0.14 (GNU/Linux)
    Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org/
    
    iEYEARECAAYFAkt66IQACgkQS2KysvBH1xmhuACbBL6u9x1WUt/wG2F45y2jjkHs
    WIIAn0tgLrLQGODyeK5pI8cPBIqsslNL
    =Fk9e
    -----END PGP SIGNATURE-----
    
    
    
    

    --- End Message ---
    --- Begin Message ---
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA1
    
    - ------------------------------------------------------------------------
                      VMware Security Advisory
    
    Advisory ID:       VMSA-2010-0004
    Synopsis:          ESX Service Console and vMA third party updates
    Issue date:        2010-03-03
    Updated on:        2010-03-03 (initial release of advisory)
    CVE numbers:       CVE-2009-2905 CVE-2008-4552 CVE-2008-4316
                      CVE-2009-1377 CVE-2009-1378 CVE-2009-1379
                      CVE-2009-1386 CVE-2009-1387 CVE-2009-0590
                      CVE-2009-4022 CVE-2009-3560 CVE-2009-3720
                      CVE-2009-2904 CVE-2009-3563 CVE-2009-2695
                      CVE-2009-2849 CVE-2009-2695 CVE-2009-2908
                      CVE-2009-3228 CVE-2009-3286 CVE-2009-3547
                      CVE-2009-3613 CVE-2009-3612 CVE-2009-3620
                      CVE-2009-3621 CVE-2009-3726 CVE-2008-3916
                      CVE-2009-1189 CVE-2009-0115
    
    - ------------------------------------------------------------------------
    
    1. Summary
    
      ESX Service Console updates for newt, nfs-utils, and glib2 packages.
    
      vMA updates for newt, nfs-util, glib2, kpartx, libvolume-id,
      device-mapper-multipath, fipscheck, dbus, dbus-libs, ed, openssl,
      bind, expat, openssh, ntp and kernel packages.
    
    2. Relevant releases
    
      VMware ESX 4.0.0 without patch ESX400-201002404-SG, ESX400-201002407-SG,
                                     ESX400-201002406-SG
    
      VMware vMA 4.0 before patch 3
    
    3. Problem Description
    
    a. vMA and Service Console update for newt to 0.52.2-12.el5_4.1
    
       Newt is a programming library for color text mode, widget based
       user interfaces. Newt can be used to add stacked windows, entry
       widgets, checkboxes, radio buttons, labels, plain text fields,
       scrollbars, etc., to text mode user interfaces.
    
       A heap-based buffer overflow flaw was found in the way newt
       processes content that is to be displayed in a text dialog box.
       A local attacker could issue a specially-crafted text dialog box
       display request (direct or via a custom application), leading to a
       denial of service (application crash) or, potentially, arbitrary
       code execution with the privileges of the user running the
       application using the newt library.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the name CVE-2009-2905 to this issue.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      ESX400-201002406-SG
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    b. vMA and Service Console update for vMA package nfs-utils to
       1.0.9-42.el5
    
       The nfs-utils package provides a daemon for the kernel NFS server
       and related tools.
    
       It was discovered that nfs-utils did not use tcp_wrappers
       correctly.  Certain hosts access rules defined in "/etc/hosts.allow"
       and "/etc/hosts.deny" may not have been honored, possibly allowing
       remote attackers to bypass intended access restrictions.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the name CVE-2008-4552 to this issue.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      ESX400-201002407-SG
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    c. vMA and Service Console package glib2 updated to 2.12.3-4.el5_3.1
    
       GLib is the low-level core library that forms the basis for projects
    such
       as GTK+ and GNOME. It provides data structure handling for C,
       portability wrappers, and interfaces for such runtime functionality
       as an event loop, threads, dynamic loading, and an object system.
    
       Multiple integer overflows in glib/gbase64.c in GLib before 2.20
       allow context-dependent attackers to execute arbitrary code via a
       long string that is converted either from or to a base64
       representation.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the name CVE-2008-4316 to this issue.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      ESX400-201002404-SG
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    d. vMA and Service Console update for openssl to 0.9.8e-12.el5
    
       SSL is a toolkit implementing SSL v2/v3 and TLS protocols with full-
       strength cryptography world-wide.
    
       Multiple denial of service flaws were discovered in OpenSSL's DTLS
       implementation. A remote attacker could use these flaws to cause a
       DTLS server to use excessive amounts of memory, or crash on an
       invalid memory access or NULL pointer dereference.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the names CVE-2009-1377, CVE-2009-1378,
       CVE-2009-1379, CVE-2009-1386, CVE-2009-1387 to these issues.
    
       An input validation flaw was found in the handling of the BMPString
       and UniversalString ASN1 string types in OpenSSL's
       ASN1_STRING_print_ex() function. An attacker could use this flaw to
       create a specially-crafted X.509 certificate that could cause
       applications using the affected function to crash when printing
       certificate contents.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the name CVE-2009-0590 to this issue.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      affected, patch pending
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    e. vMA and Service Console package bind updated to 9.3.6-4.P1.el5_4.1
    
       It was discovered that BIND was incorrectly caching responses
       without performing proper DNSSEC validation, when those responses
       were received during the resolution of a recursive client query
       that requested DNSSEC records but indicated that checking should be
       disabled. A remote attacker could use this flaw to bypass the DNSSEC
       validation check and perform a cache poisoning attack if the target
       BIND server was receiving such client queries.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the name CVE-2009-4022 to this issue.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not applicable
    
       ESX            4.0       ESX      affected, patch pending
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    f. vMA and Service Console package expat updated to 1.95.8-8.3.el5_4.2.
    
       Two buffer over-read flaws were found in the way Expat handled
       malformed UTF-8 sequences when processing XML files. A specially-
       crafted XML file could cause applications using Expat to fail while
       parsing the file.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the names CVE-2009-3560 and CVE-2009-3720 to these
       issues.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not applicable
    
       ESX            4.0       ESX      affected, patch pending
       ESX            3.5       ESX      affected, patch pending
       ESX            3.0.3     ESX      affected, patch pending
       ESX            2.5.5     ESX      affected, patch pending
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    g. vMA and Service Console package openssh update to 4.3p2-36.el5_4.2
    
       A Red Hat specific patch used in the openssh packages as shipped in
       Red Hat Enterprise Linux 5.4 (RHSA-2009:1287) loosened certain
       ownership requirements for directories used as arguments for the
       ChrootDirectory configuration options. A malicious user that also
       has or previously had non-chroot shell access to a system could
       possibly use this flaw to escalate their privileges and run
       commands as any system user.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the name CVE-2009-2904 to this issue.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not applicable
    
       ESX            4.0       ESX      affected, patch pending
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    h. vMA and Service Console package ntp updated to
       ntp-4.2.2p1-9.el5_4.1.i386.rpm
    
       A flaw was discovered in the way ntpd handled certain malformed NTP
       packets. ntpd logged information about all such packets and replied
       with an NTP packet that was treated as malformed when received by
       another ntpd. A remote attacker could use this flaw to create an NTP
       packet reply loop between two ntpd servers through a malformed packet
       with a spoofed source IP address and port, causing ntpd on those
       servers to use excessive amounts of CPU time and fill disk space with
       log messages.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    
    has assigned the name CVE-2009-3563 to this issue.
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not applicable
    
       ESX            4.0       ESX      affected, patch pending
       ESX            3.5       ESX      affected, patch pending
       ESX            3.0.3     ESX      affected, patch pending
       ESX            2.5.5     ESX      affected, patch pending
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    i. vMA update for package kernel to 2.6.18-164.9.1.el5
    
       Updated vMA package kernel addresses the security issues listed
       below.
    
       The Common Vulnerabilities and Exposures project (cve.mitre.org)
       has assigned the name CVE-2009-2849 to the security issue fixed in
       kernel 2.6.18-128.2.1
    
       The Common Vulnerabilities and Exposures project (cve.mitre.org)
       has assigned the names CVE-2009-2695, CVE-2009-2908, CVE-2009-3228,
       CVE-2009-3286, CVE-2009-3547, CVE-2009-3613 to the security issues
       fixed in kernel 2.6.18-128.6.1
    
       The Common Vulnerabilities and Exposures project (cve.mitre.org)
       has assigned the names CVE-2009-3612, CVE-2009-3620, CVE-2009-3621,
       CVE-2009-3726 to the security issues fixed in kernel
       2.6.18-128.9.1
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      affected, patch pending
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3 **
    
     * hosted products are VMware Workstation, Player, ACE, Fusion.
    
     ** vMA is updated to kernel version 2.6.18-164.9.1
    
    j. vMA 4.0 updates for the packages kpartx, libvolume-id,
       device-mapper-multipath, fipscheck, dbus, dbus-libs, and ed
    
       kpartx updated to 0.4.7-23.el5_3.4, libvolume-id updated to
       095-14.20.el5 device-mapper-multipath package updated to
       0.4.7-23.el5_3.4, fipscheck updated to 1.0.3-1.el5, dbus
       updated to 1.1.2-12.el5, dbus-libs updated to 1.1.2-12.el5,
       and ed package updated to 0.2-39.el5_2.
    
       The Common Vulnerabilities and Exposures Project (cve.mitre.org)
       has assigned the names CVE-2008-3916, CVE-2009-1189 and
       CVE-2009-0115 to these issues.
    
       The following table lists what action remediates the vulnerability
       (column 4) if a solution is available.
    
       VMware         Product   Running  Replace with/
       Product        Version   on       Apply Patch
       =============  ========  =======  =================
       VirtualCenter  any       Windows  not affected
    
       hosted *       any       any      not affected
    
       ESXi           any       ESXi     not affected
    
       ESX            4.0       ESX      not affected
       ESX            3.5       ESX      not affected
       ESX            3.0.3     ESX      not affected
       ESX            3.0.2     ESX      not affected
       ESX            2.5.5     ESX      not affected
    
       vMA            4.0       RHEL5    Patch 3
    
     * hosted products are VMware Workstation, Player, ACE, Server, Fusion.
    
    4. Solution
    
      Please review the patch/release notes for your product and version
      and verify the md5sum of your downloaded file.
    
      ESX 4.0
      -------
    
    https://hostupdate.vmware.com/software/VUM/OFFLINE/release-192-20100228-732
    240/ESX400-201002001.zip
      md5sum: de62cbccaffa4b2b6831617f18c1ccb4
      sha1sum: 4083f191fa4acd6600c9a87e4852f9f5700e91ab
      http://kb.vmware.com/kb/1018403
    
      Note: ESX400-201002001 contains the following security bulletins
      ESX400-201002404-SG, ESX400-201002407-SG, and ESX400-201002406-SG.
    
      To install an individual bulletin use esxupdate with the -b option.
      esxupdate --bundle ESX400-201002001.zip -b ESX400-201002404-SG \
      -b ESX400-201002407-SG -b ESX400-201002406-SG update
    
      vMA 4.0
      -------
      To update VIMA
          1 Log in to VIMA as vi-admin.
          2 type 'sudo /usr/sbin/vima-update update' this will apply all
            currently available updates.  See http://tinyurl.com/yfekgrx
            for more information.
    
    5. References
    
      CVE numbers
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2905
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4552
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4316
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1377
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1378
    
    http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1379 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1386
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1387
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4022
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3560
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3720
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2904
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2695
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2849
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2695
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2908
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3228
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3613
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3612
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-3916
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1189
      http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0115
    
    - ------------------------------------------------------------------------
    6. Change log
    
    2010-03-03  VMSA-2010-0004
    Initial security advisory after release of bulletins for ESX 4.0
    on 2010-03-03 and release of vMA Patch 3 on 2010-02-25.
    
    - -----------------------------------------------------------------------
    7. Contact
    
    E-mail list for product security notifications and announcements:
    http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce
    
    This Security Advisory is posted to the following lists:
    
     * security-announce at lists.vmware.com
     * bugtraq at securityfocus.com
     * full-disclosure at lists.grok.org.uk
    
    E-mail:  security at vmware.com
    PGP key at: http://kb.vmware.com/kb/1055
    
    VMware Security Center
    http://www.vmware.com/security
    
    VMware security response policy
    http://www.vmware.com/support/policies/security_response.html
    
    General support life cycle policy
    http://www.vmware.com/support/policies/eos.html
    
    VMware Infrastructure support life cycle policy
    http://www.vmware.com/support/policies/eos_vi.html
    
    Copyright 2010 VMware Inc.  All rights reserved.
    
    -----BEGIN PGP SIGNATURE-----
    Version: PGP Desktop 9.8.3 (Build 4028)
    Charset: utf-8
    
    wj8DBQFLj1c6S2KysvBH1xkRAnl5AJ9RcHVB7qooSwOPFdVoDFTjohDypgCfZ44O
    2z0ICIcntM88ZONMfDNUM6Y=
    =14fN
    -----END PGP SIGNATURE-----
    
    
    
    
    

    --- End Message ---

    Vissza a www.andrews.hu-ra