Threat Level: green Handler on Duty: Johannes Ullrich

SANS ISC: VMware Updates SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
VMware Updates

VMware released one new security advisory, and updated 2 older once.

New: VMSA-2012-0013 [1]

The update affects vCenter (and Update Manager) 4.1 without Update 3, as well as ESX/ESXi. It patches a number of open source components that are included as part of VMware: Apache struts, popt/rpm, glibc, libxm2, Perl, OpenSSL, JRE and the Linux Kernel.

An interesting update is the update of Java, which is included in ESX. Some of the older versions of ESX and vCenter still use Java 1.5, which was left out of the recent issues. However, for those VMware products that do use Java 1.6, only update 31 is provided. As of yesterday, Update 35 is "current". 

Updated: 

VMSA-2012-0005.2 [2]:  Added Windows 7 information
VMSA-2012-0012.1 [3]: included information about vSphere 4.1 U3

 

[1] http://www.vmware.com/security/advisories/VMSA-2012-0013.html
[2] http://www.vmware.com/security/advisories/VMSA-2012-0005.html
[3] http://www.vmware.com/security/advisories/VMSA-2012-0012.html

------
Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

I will be teaching next: Defending Web Applications Security Essentials - SANS San Francisco Winter 2019

Johannes

3675 Posts
ISC Handler

Sign Up for Free or Log In to start participating in the conversation!