Bugtraq mailing list archives

VMSA-2010-0013 VMware ESX third party updates for Service Console


From: VMware Security Team <security () vmware com>
Date: Tue, 31 Aug 2010 23:34:33 -0700

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
                  VMware Security Advisory

Advisory ID:       VMSA-2010-0013
Synopsis:          VMware ESX third party updates for Service Console
Issue date:        2010-08-31
Updated on:        2010-08-31 (initial release of advisory)
CVE numbers:       CVE-2005-4268 CVE-2010-0624 CVE-2010-2063
                  CVE-2010-1321 CVE-2010-1168 CVE-2010-1447
- ------------------------------------------------------------------------

1. Summary

  ESX 3.5 Console OS (COS) updates for COS packages perl, krb5, samba,
  tar, and cpio.

2. Relevant releases

  VMware ESX 3.5 without patches ESX350-201008405-SG,
  ESX350-201008407-SG, ESX350-201008410-SG, ESX350-201008411-SG,
  ESX350-201008412-SG.

  Notes:
  Effective May 2010, VMware's patch and update release program during
  Extended Support will be continued with the condition that all
  subsequent patch and update releases will be based on the latest
  baseline release version as of May 2010 (i.e. ESX 3.0.3 Update 1,
  ESX 3.5 Update 5, and VirtualCenter 2.5 Update 6). Refer to section
  "End of Product Availability FAQs" at
  http://www.vmware.com/support/policies/lifecycle/vi/faq.html for
  details.

  Extended support for ESX 3.0.3 ends on 2011-12-10.  Users should plan
  to upgrade to at least ESX 3.5 and preferably to the newest release
  available.

3. Problem Description

a. Service Console update for cpio

   The service console package cpio is updated to version 2.5-6.RHEL3.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the names CVE-2005-4268 and CVE-2010-0624 to the issues
   addressed in this update.

   Column 4 of the following table lists the action required to
   remediate the vulnerability in each release, if a solution is
available.
   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch
   =============  ========  =======  =================
   VirtualCenter  any       Windows  not affected

   hosted *       any       any      not affected

   ESXi           any       ESXi     not affected

   ESX            4.1       ESX      affected, patch pending
   ESX            4.0       ESX      affected, patch pending
   ESX            3.5       ESX      ESX350-201008405-SG
   ESX            3.0.3     ESX      affected, patch pending

 * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

b. Service Console update for tar

   The service console package tar is updated to version
   1.13.25-16.RHEL3

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2010-0624 to the issue addressed in this
   update.

   Column 4 of the following table lists the action required to
   remediate the vulnerability in each release, if a solution is
available.
   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch
   =============  ========  =======  =================
   VirtualCenter  any       Windows  not affected

   hosted *       any       any      not affected

   ESXi           any       ESXi     not affected

   ESX            4.1       ESX      affected, patch pending
   ESX            4.0       ESX      affected, patch pending
   ESX            3.5       ESX      ESX350-201008407-SG
   ESX            3.0.3     ESX      affected, patch pending

 * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

c. Service Console update for samba

   The service console packages for samba are updated to version
   samba-3.0.9-1.3E.17vmw, samba-client-3.0.9-1.3E.17vmw and
   samba-common-3.0.9-1.3E.17vmw.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2010-2063 to the issue addressed in this
   update.

   Note:
   The issue mentioned above is present in the Samba server (smbd) and
   is not present in the Samba client or Samba common packages.

   To determine if your system has Samba server installed do a
   'rpm -q samba`.

   The following lists when the Samba server is installed on the ESX
   service console:

   - ESX 4.0, ESX 4.1
     The Samba server is not present on ESX 4.0 and ESX 4.1.

   - ESX 3.5
     The Samba server is present if an earlier patch for Samba has been
     installed.

   - ESX 3.0.3
     The Samba server is present if ESX 3.0.3 was upgraded from an
     earlier version of ESX 3 and a Samba patch was installed on that
     version.

   The Samba server is not needed to operate the service console and
   can be be disabled without loss of functionality to the service
   console.

   Column 4 of the following table lists the action required to
   remediate the vulnerability in each release, if a solution is
available.
   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch
   =============  ========  =======  =================
   VirtualCenter  any       Windows  not affected

   hosted *       any       any      not affected

   ESXi           any       ESXi     not affected

   ESX            4.1       ESX      not applicable
   ESX            4.0       ESX      not applicable
   ESX            3.5       ESX      ESX350-201008410-SG
   ESX            3.0.3     ESX      affected, patch pending

 * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

d. Service Console update for krb5

   The service console package krb5 is updated to version 1.2.7-72.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the name CVE-2010-1321 to the issue addressed in this
   update.

   Column 4 of the following table lists the action required to
   remediate the vulnerability in each release, if a solution is
available.
   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch
   =============  ========  =======  =================
   VirtualCenter  any       Windows  not affected

   hosted *       any       any      not affected

   ESXi           any       ESXi     not affected

   ESX            4.1       ESX      affected, patch pending
   ESX            4.0       ESX      affected, patch pending
   ESX            3.5       ESX      ESX350-201008411-SG
   ESX            3.0.3     ESX      affected, patch pending

 * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

e. Service Console update for perl

   The service console package perl is updated to version
   5.8.0-101.EL3.

   The Common Vulnerabilities and Exposures project (cve.mitre.org)
   has assigned the names CVE-2010-1168 and CVE-2010-1447 to the issue
   addressed in this update.

   Column 4 of the following table lists the action required to
   remediate the vulnerability in each release, if a solution is
available.
   VMware         Product   Running  Replace with/
   Product        Version   on       Apply Patch
   =============  ========  =======  =================
   VirtualCenter  any       Windows  not affected

   hosted *       any       any      not affected

   ESXi           any       ESXi     not affected

   ESX            4.1       ESX      affected, patch pending
   ESX            4.0       ESX      affected, patch pending
   ESX            3.5       ESX      ESX350-201008412-SG
   ESX            3.0.3     ESX      affected, patch pending

 * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

4. Solution

  Please review the patch/release notes for your product and version
  and verify the md5sum of your downloaded file.

  ESX 3.5
  -------

  ESX350-201008405-SG (cpio)
  -------------------
  http://download3.vmware.com/software/vi/ESX350-201008405-SG.zip
  md5sum: e1d5464ab9886f93dc47ffe7b50e6246
  http://kb.vmware.com/kb/1026130

  ESX350-201008407-SG (tar)
  -------------------
  http://download3.vmware.com/software/vi/ESX350-201008407-SG.zip
  md5sum: 574013a102fb523c7a97c1acb05f63ea
  http://kb.vmware.com/kb/1026132

  ESX350-201008410-SG (samba)
  -------------------
  http://download3.vmware.com/software/vi/ESX350-201008410-SG.zip
  md5sum: c5224cf4218a3636b70207b8d269d024
  http://kb.vmware.com/kb/1026134

  ESX350-201008411-SG (krb5)
  -------------------
  http://download3.vmware.com/software/vi/ESX350-201008411-SG.zip
  md5sum: c0f8b642f8eddd91c959e262d1b7f181
  http://kb.vmware.com/kb/1026135

  ESX350-201008412-SG (perl)
  -------------------
  http://download3.vmware.com/software/vi/ESX350-201008412-SG.zip
  md5sum: 30e176f34e49c055b0485dfc921fbf81
  http://kb.vmware.com/kb/1026137

5. References

  CVE numbers
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-4268
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0624
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-2063
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1321
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1168
  http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-1447

- ------------------------------------------------------------------------

6. Change log

2010-08-31  VMSA-2010-0013
Initial security advisory after release of patches for ESX 3.5
on 2010-08-31

- -----------------------------------------------------------------------
7. Contact

E-mail list for product security notifications and announcements:
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce

This Security Advisory is posted to the following lists:

 * security-announce at lists.vmware.com
 * bugtraq at securityfocus.com
 * full-disclosure at lists.grok.org.uk

E-mail:  security at vmware.com
PGP key at: http://kb.vmware.com/kb/1055

VMware Security Center
http://www.vmware.com/security

VMware security response policy
http://www.vmware.com/support/policies/security_response.html

General support life cycle policy
http://www.vmware.com/support/policies/eos.html

VMware Infrastructure support life cycle policy
http://www.vmware.com/support/policies/eos_vi.html

Copyright 2010 VMware Inc.  All rights reserved.


-----BEGIN PGP SIGNATURE-----
Version: PGP Desktop 9.8.3 (Build 4028)
Charset: utf-8

wj8DBQFMffPwS2KysvBH1xkRAvXwAJ4skfzL8KP0a0OFA3VrUwSN0zMB6wCcC/yB
xiPGukMjKtDy6B2f6/hB/LE=
=PAp4
-----END PGP SIGNATURE-----


Current thread: