VMware Issues Security Updates for ESX, VirtualCenter

Get up to speed on VMware's latest security issues: Pointers to details and patches here.

By David Marshall

CONNECTIONS
VMware
Wed, October 08, 2008InfoWorld

VMware has recently released a set of new updates and patches for a number of its products to help address several security issues that have been identified. These multiple security issues are described in a new security announcement covering VMware VirtualCenter 2.5 Update 3 and patches for ESX and ESXi. There is also an updated VMware security advisory that details information on other VMware products such as Workstation, Player, ACE, Server, and VCB.

VMware released updates for ESX and ESXi as well as an Update 3 patch for VirtualCenter 2.5. One reason why people are flocking to virtualization is because it offers an easy high-availability solution, and this is one area that is being addressed with the latest round of patching. A number of issues have been addressed with VMware High Availability: network compliance checking, HA-DRS clustering and maintenance mode, advanced settings, and user permission issues.

VMware VirtualCenter Update 3 also addresses potential information disclosure and updates to Java JRE packages. The new update resolves an issue where a user's password could be displayed in cleartext. When logging into VirtualCenter Server 2.0 with Virtual Infrastructure Client 2.5, the user password might be displayed if it contains certain special characters. The dialog box displaying the password can appear in front or hidden behind other windows. The patch also updates the JRE package to Version 1.5.0_16, which addresses multiple security issues that existed in the previous version of JRE.

You can read more about these issues in the VirtualCenter 2.5 Update 3 Release Notes.

The latest security advisory also addresses an in-guest privilege escalation on 64-bit guest operating systems in ESX, ESXi, and previously released versions of the company's hosted product line. A flaw in VMware's CPU hardware emulation could allow the virtual CPU to jump to an incorrect memory address. Exploitation of this issue on the guest operating system does not lead to a compromise of the host system but could lead to a privilege escalation on the guest operating system.

And updates to VMware Workstation, Player, ACE, Server, and VCB also address information disclosure, privilege escalation, and other security issues.

One of the ISAPI extensions provided by VMware is vulnerable to a remote denial of service attack. By sending a malformed request, IIS might shut down. IIS 6.0 restarts automatically, but IIS 5.0 does not when its Startup Type is set to Manual.

This release also fixes privilege escalation vulnerabilities in host systems. Exploitation of this vulnerability allows users to run arbitrary code on the host system with elevated privileges.

VMware

More from IT Drilldown « Back to Virtualization
CASE STUDY
Disaster Can Inspire Quick Move to Desktop Virtualization
In the wake of a hurricane, a Texas hospital system's IT group overcame user reluctance to virtualize desktop PCs. Here's a look at their journey and the thorny little issue that Citrix just solved a few weeks ago: USB port support. Full Story »

Loading...
Virtualization Vendor Matrix

Find out what vendors offer the products you need.

View the Vendor Matrix »
Virtualization MarketSpace
 
SPONSORED LINKS
 

Removing Barriers To Better Server Virtualization Efficiency

Global Research: CIOs Weigh In On Virtualization

5 Key Virtualization Management Challenges

Upgrading to VMware vSphere with vWire

Maximizing website Return on Information with high-quality search

See how AT&T can help protect your network.

Webcast: Unleashing the Power of Customer Data

White Paper: Improve Agility with Operational Responsiveness

White Paper: Legacy Tools: Not Built for the Helpdesk

Secure Email and Web-Based Communication from Evolving Attacks

WagerWorks Takes Fraudsters Out of the Game using iovation

Seven Design Requirements for Web 2.0 Threat Protection

Increase UPS efficiency without sacrificing protection.

Learn how advanced forecasting tools can deliver significant business results for global corporations.

Lower IT Costs with Oracle Database 11g Release 2

White Paper: Visibility and the New Normal of Mobile Work

Taking the Service Desk to the Next Level

Learn about The Information Technology Infrastructure Library.

Return on Information: Google Enterprise Search pays you back. Get the facts.

VMware. The source for Business Infrastructure Virtualization.

ShoreTel tells businesses to untangle from competitors' complexity and turn to its brilliantly simple UC solution

Top Five CIO Challenges

Read the RSA report: Security for Business Innovation

64-page prescriptive guide to security, compliance, and IT operations.

A Clear View Toward Virtualization

White Paper: Right-Sizing Your Power Infrastructure

Taking a Seat at the Executive Table: The Reality of Virtualization

Server Consolidation: Leveraging the Benefits of Virtualization

Return on Information: Google Enterprise Search pays you back

Cut Costs & Green Your IT Operations with PC Power Management

White Paper: 4 Customer Service Myths

White Paper: Managed Security for a Not-So-Secure World

White Paper: 5 Best Practices for Smartphone Support

White Paper: Next Generation Remote Infrastructure Management

Keeping Your Members Safe from Online Scams and Predators

The Total Economic Impact of Network Security Intrusion Prevention

Generation Remote Infrastructure Management - Changing the Paradigm

Cloud-Based Email Management: Opinion Shifts In Favor

eBook: How Can You Make Your People Productive Anywhere?

Achieving Business Agility with Application Grid

Ready to virtualize tier one applications? Check your virtualization maturity.

Seven Ways ITIL Can Help You in an Economic Downturn

Tips for successful virtualization management.

AT&T Synaptic Storage as a Service. Expand on demand

Trend Micro ranked #1 against real-world malware. Read more.

Webinar: Jump-start your in-house e-discovery with Ringtail QuickCull from FTI Technology

Streamline IT Costs. Boost Performance with WAN Optimization.

Build your 1st app FREE with Force.com

TDWI checklist helps define data readiness for analytics. Download report.

eZine: A Roadmap to Reducing IT Complexity

 
 
RESOURCE CENTER