Virtualization Technology News and Information
Article
RSS
VMware Security Advisory Updated - ESX Packages for libxml2, ucd-snmp, libtiff

Updated ESX packages for libxml2, ucd-snmp, libtiff

 

Advisory ID:       VMSA-2008-0017

Synopsis:          Updated ESX packages for libxml2, ucd-snmp, libtiff

Issue date:        2008-10-31

Updated on:        2008-10-31 (initial release of advisory)

 

Relevant releases

 

   ESX 3.0.3 without patch ESX303-200810503-SG

   ESX 3.0.2 without patch ESX-1006968

   ESX 2.5.5 before Upgrade Patch 10

   ESX 2.5.4 before Upgrade Patch 21

 

   NOTE: Extended support (Security and Bug fixes) for ESX 3.0.2 ended

         on 2008-10-29. Extended support (Security and Bug fixes) for

         ESX 2.5.4 ended on 2008-10-08.

 

         Extended support for ESX 3.0.2 Update 1 ends on 2009-08-08. Users

         should plan to upgrade to ESX 3.0.3 and preferably to the newest

         release available.

 

3. Problem Description

 

 a. Updated ESX Service Console package libxml2

 

    A denial of service flaw was found in the way libxml2 processes

    certain content. If an application that is linked against

    libxml2 processes malformed XML content, the XML content might

    cause the application to stop responding.

 

    The Common Vulnerabilities and Exposures project (cve.mitre.org)

    has assigned the name CVE-2008-3281 to this issue.

 

    The following table lists what action remediates the vulnerability

    (column 4) if a solution is available.

 

    VMware         Product   Running  Replace with/

    Product        Version   on       Apply Patch

    =============  ========  =======  =================

    VirtualCenter  any       Windows  not affected

 

    hosted         any       any      not affected

 

    ESXi           3.5       ESXi     not affected

 

    ESX            3.5       ESX      affected, patch pending

    ESX            3.0.3     ESX      ESX303-200810503-SG

    ESX            3.0.2     ESX      ESX-1006968

    ESX            2.5.5     ESX      ESX 2.5.5 upgrade patch 10 or later

    ESX            2.5.4     ESX      ESX 2.5.4 upgrade patch 21

 

    * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 

 b. Updated ESX Service Console package ucd-snmp

 

    A flaw was found in the way ucd-snmp checks an SNMPv3 packet's

    Keyed-Hash Message Authentication Code. An attacker could use

    this flaw to spoof an authenticated SNMPv3 packet.

 

    The Common Vulnerabilities and Exposures project (cve.mitre.org)

    has assigned the name CVE-2008-0960 to this issue.

 

    The following table lists what action remediates the vulnerability

    (column 4) if a solution is available.

 

    VMware         Product   Running  Replace with/

    Product        Version   on       Apply Patch

    =============  ========  =======  =================

    VirtualCenter  any       Windows  not affected

 

    hosted         any       any      not affected

 

    ESXi           3.5       ESXi     not affected

 

    ESX            3.5       ESX      not affected

    ESX            3.0.3     ESX      not affected

    ESX            3.0.2     ESX      not affected

    ESX            2.5.5     ESX      ESX 2.5.5 upgrade patch 10 or later

    ESX            2.5.4     ESX      ESX 2.5.4 upgrade patch 21

 

    * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 

 c. Updated third party library libtiff

 

    Multiple uses of uninitialized values were discovered in libtiff's

    Lempel-Ziv-Welch (LZW) compression algorithm decoder. An attacker

    could create a carefully crafted LZW-encoded TIFF file that would

    cause an application linked with libtiff to crash or, possibly,

    execute arbitrary code.

 

    The Common Vulnerabilities and Exposures project (cve.mitre.org)

    has assigned the name CVE-2008-2327 to this issue.

 

    The following table lists what action remediates the vulnerability

    (column 4) if a solution is available.

 

    VMware         Product   Running  Replace with/

    Product        Version   on       Apply Patch

    =============  ========  =======  =================

    VirtualCenter  any       Windows  not affected

 

    hosted         any       any      not affected

 

    ESXi           3.5       ESXi     not affected

 

    ESX            3.5       ESX      not affected

    ESX            3.0.3     ESX      not affected

    ESX            3.0.2     ESX      not affected

    ESX            2.5.5     ESX      ESX 2.5.5 upgrade patch 10 or later

    ESX            2.5.4     ESX      ESX 2.5.4 upgrade patch 21

 

    * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 

4. Solution

 

   Please review the patch/release notes for your product and version

   and verify the md5sum of your downloaded file.

 

   ESX

   ---

   ESX 3.0.3 patch ESX303-200810503-SG

   http://download3.vmware.com/software/vi/ESX303-200810503-SG.zip

   md5sum: e687313e58377be41f6e6b767dfbf268

   http://kb.vmware.com/kb/1006971

 

   ESX 3.0.2 patch ESX-1006968

   http://download3.vmware.com/software/vi/ESX-1006968.tgz

   md5sum: fc9e30cff6f03a209e6a275254fa6719

   http://kb.vmware.com/kb/1006968

 

   VMware ESX 2.5.5 Upgrade Patch 10

   http://download3.vmware.com/software/esx/esx-2.5.5-119702-upgrade.tar.gz

   md5sum: 2ee87cdd70b1ba84751e24c0bd8b4621

   http://vmware.com/support/esx25/doc/esx-255-200810-patch.html

 

   VMware ESX 2.5.4 Upgrade Patch 21

   http://download3.vmware.com/software/esx/esx-2.5.4-119703-upgrade.tar.gz

   md5sum: d791be525c604c852a03dd7df0eabf35

   http://vmware.com/support/esx25/doc/esx-254-200810-patch.html

 

Published Friday, October 31, 2008 6:49 AM by David Marshall
Filed under:
Comments
There are no comments for this post.
To post a comment, you must be a registered user. Registration is free and easy! Sign up now!
Calendar
<October 2008>
SuMoTuWeThFrSa
2829301234
567891011
12131415161718
19202122232425
2627282930311
2345678