Advertisement
Promo

Security threats Toolkit

VMware patches hypervisor bugs

Tom Espiner ZDNet.co.uk

Published: 19 Sep 2008 16:54 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

A patch is available for a buffer overflow vulnerability in VMware's flagship ESX 3.5 and ESXi 3.5 hypervisors.

The flaw and a patch were announced in VMware Security Advisory VMSA-2008-0015 on Thursday.

The vulnerability lies in the Openwsman system management platform, which implements VMware's web services management protocol. Buffer overflows could occur while Openwsman decodes HTTP basic authentication headers, the company said.

ZDNet.co.uk blogs

Come and talk to ZDNet

We're inviting people to join us in a breakfast briefing on virtualisation...

Find out more +

Patches are linked to on VMware's site in security advisory VMSA-2008-0015.

VMware also re-released two advisories with additional patches. VMSA-2008-0014 has added fixes for libpng and bind for ESX 3.5 servers, while VMSA-2008-0013 has added fixes for net-snmp and perl for ESX 3.5 servers, security training organisation Sans noted on its blog.

Last month, VMware customers had to contend with their virtual machines not turning on after a licensing mistake by VMware.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters