VMware patches hypervisor bugs

By Tom Espiner, ZDNet UK
Monday, September 22, 2008 10:56 AM

A patch is available for a buffer overflow vulnerability in VMware's flagship ESX 3.5 and ESXi 3.5 hypervisors.

The flaw and a patch were announced in VMware Security Advisory VMSA-2008-0015 on Thursday.

The vulnerability lies in the Openwsman system management platform, which implements VMware's Web services management protocol. Buffer overflows could occur while Openwsman decodes HTTP basic authentication headers, the company said.

Patches are linked to on VMware's site in security advisory VMSA-2008-0015.

VMware also re-released two advisories with additional patches. VMSA-2008-0014 has added fixes for libpng and bind for ESX 3.5 servers, while VMSA-2008-0013 has added fixes for net-snmp and perl for ESX 3.5 servers, security training organization Sans noted on its blog.

Last month, VMware customers had to contend with their virtual machines not turning on after a licensing mistake by VMware.


WORTHWHILE?

0

0 votes
Blog

Talkback 0 comments

There are currently no comments for this post.


Tech Jobs Now!

Search for your ideal tech job:

Cost and graphics concerns delay a VDI project

Tech Management

Virtual desktops are a serious paradigm shift and Scott Lowe is taking it in a slow and measured way. In this article, he provides an update on ongoing VDI efforts at Westminster College.


Read more »



Do we need more delivery centers?

Blog thumbnail

As I wrote a while back in about "racing to subsidies", there certainly is an increased focus by governments to attract delivery centers to their region. To do that, many..... by Michael Rehkopf

Read more »

Tags

  1. attack
  2. authentication and encryption
  3. blog
  4. data security
  5. e - mail
  6. hacking
  7. internet
  8. malware
  9. microsoft corp.
  10. network
  11. network security
  12. pc security
  13. researcher
  14. security
  15. security management
  16. software
  17. spam and phishing
  18. symantec corp.
  19. viruses and worms
  20. web