VMware Security Advisory has announced three new advisory alerts and patches for VMware ESX.
1. In VMSA-2009-0001.1, the ESX patches address an issue loading corrupt virtual disks and it updates Service Console packages for net-snmp and libxml2.
2. In VMSA-2009-0003, the ESX 2.5.5 patch 12 Build 142708 updates the service console package ed
3. In VMSA-2009-0002, VMware VirtualCenter Update 4 updates Tomcat to 5.5.27 which addresses multiple security issues that existed in the previous version of Apache Tomcat.
I'm not sure how many folks are still running ESX 2.5.x? Is there anyone out there doing so? If so, why? Just curious why you haven't upgraded to either 3.0.x, or 3.5.x.
And in interesting note from VMware: Extended support for ESX 2.5.5 ends on 2010-06-15. Users should plan to upgrade to ESX 3.0.3 and preferably to the newest release available. Extended support for ESX 3.5 Update 1 ends on 7/25/2009, users should plan to upgrade to at least ESX 3.5 Update 2 by that time. Extended support for ESX 3.0.2 Update 1 ends on 2009-08-08. Users should plan to upgrade to ESX 3.0.3 and preferably to the newest release available.