Anfälligkeitssuche        Suche in 202850 CVE Beschreibungen
und 87302 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:
Kategorie:VMware Local Security Checks
Titel:VMware ESXi utilities and ESX Service Console third party updates (VMSA-2010-0009)
Zusammenfassung:The remote ESXi is missing one or more security related Updates from VMSA-2010-0009.
The remote ESXi is missing one or more security related Updates from VMSA-2010-0009.

Vulnerability Insight:
ESXi update for ntp and ESX Console OS (COS) updates for COS kernel, openssl, krb5, gcc, bind, gzip, sudo resolve multiple security issues:

a. Service Console update for COS kernel

Updated COS package 'kernel' addresses the security issues that are fixed through versions 2.6.18-164.11.1.

b. ESXi userworld update for ntp

A vulnerability in ntpd could allow a remote attacker to cause a denial of service (CPU and bandwidth consumption) by using MODE_PRIVATE
to send a spoofed (1) request or (2) response packet that triggers a continuous exchange of MODE_PRIVATE error responses between two NTP daemons.

c. Service Console package openssl updated to 0.9.8e-12.el5_4.1

A memory leak in the zlib could allow a remote attacker to cause a denial of service (memory consumption) via vectors that trigger
incorrect calls to the CRYPTO_cleanup_all_ex_data function.

d. Service Console update for krb5 to 1.6.1-36.el5_4.1 and pam_krb5 to 2.2.14-15.

Multiple integer underflows in the AES and RC4 functionality in the crypto library could allow remote attackers to cause a denial of
service (daemon crash) or possibly execute arbitrary code by providing ciphertext with a length that is too short to be valid.

e. Service Console package bind updated to 9.3.6-4.P1.el5_4.2

A vulnerability was discovered which could allow remote attacker to add the Authenticated Data (AD) flag to a forged NXDOMAIN response
for an existing domain.

f. Service Console package gcc updated to 3.2.3-60

GNU Libtool's ltdl.c attempts to open .la library files in the current working directory. This could allow a local user to gain
privileges via a Trojan horse file. The GNU C Compiler collection (gcc) provided in ESX contains a statically linked version of the
vulnerable code, and is being replaced.

g. Service Console package gzip update to 1.3.3-15.rhel3

An integer underflow in gzip's unlzw function on 64-bit platforms may allow a remote attacker to trigger an array index error
leading to a denial of service (application crash) or possibly execute arbitrary code via a crafted LZW compressed file.

h. Service Console package sudo updated to 1.6.9p17-6.el5_4

When a pseudo-command is enabled, sudo permits a match between the name of the pseudo-command and the name of an executable file in an
arbitrary directory, which allows local users to gain privileges via a crafted executable file.

Affected Software/OS:
VMware ESXi 4.0.0 without patch ESXi400-201005401-SG

VMware ESX 4.0.0 without patches ESX400-201005401-SG, ESX400-201005406-SG, ESX400-201005408-SG, ESX400-201005407-SG, ESX400-201005405-SG, ESX400-201005409-SG

VMware ESX 3.5 without patches ESX350-201006408-SG, ESX350-201006405-SG, ESX350-201006406-SG

Apply the missing patch(es).

CVSS Score:

CVSS Vector:

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2009-2695
BugTraq ID: 36051
Debian Security Information: DSA-2005 (Google Search)
RedHat Security Advisories: RHSA-2009:1540
RedHat Security Advisories: RHSA-2009:1548
Common Vulnerability Exposure (CVE) ID: CVE-2009-2908
BugTraq ID: 36639
XForce ISS Database: kernel-ecryptfs-dos(53693)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3228
Common Vulnerability Exposure (CVE) ID: CVE-2009-3286
SuSE Security Announcement: SUSE-SA:2010:012 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3547
BugTraq ID: 36901
Bugtraq: 20100625 VMSA-2010-0010 ESX 3.5 third party update for Service Console kernel (Google Search)
RedHat Security Advisories: RHSA-2009:1541
RedHat Security Advisories: RHSA-2009:1550
SuSE Security Announcement: SUSE-SA:2009:054 (Google Search)
SuSE Security Announcement: SUSE-SA:2009:056 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:001 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3613
BugTraq ID: 36706
SuSE Security Announcement: SUSE-SA:2009:064 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3612
SuSE Security Announcement: SUSE-SA:2009:061 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3620
BugTraq ID: 36824
SuSE Security Announcement: SUSE-SA:2010:013 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3621
Common Vulnerability Exposure (CVE) ID: CVE-2009-3726
BugTraq ID: 36936
Common Vulnerability Exposure (CVE) ID: CVE-2007-4567
BugTraq ID: 26943
RedHat Security Advisories: RHSA-2010:0095
XForce ISS Database: linux-kernel-ipv6-dos(39171)
Common Vulnerability Exposure (CVE) ID: CVE-2009-4536
BugTraq ID: 37519
Debian Security Information: DSA-1996 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:005 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:007 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:010 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:014 (Google Search)
XForce ISS Database: kernel-e1000main-security-bypass(55648)
Common Vulnerability Exposure (CVE) ID: CVE-2009-4537
BugTraq ID: 37521
Debian Security Information: DSA-2053 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:023 (Google Search)
SuSE Security Announcement: SUSE-SA:2010:031 (Google Search)
XForce ISS Database: kernel-r8169-dos(55647)
Common Vulnerability Exposure (CVE) ID: CVE-2009-4538
BugTraq ID: 37523
XForce ISS Database: kernel-edriver-unspecified(55645)
Common Vulnerability Exposure (CVE) ID: CVE-2006-6304
BugTraq ID: 21591
RedHat Security Advisories: RHSA-2010:0046
Common Vulnerability Exposure (CVE) ID: CVE-2009-2910
BugTraq ID: 36576
Common Vulnerability Exposure (CVE) ID: CVE-2009-3080
BugTraq ID: 37068
Common Vulnerability Exposure (CVE) ID: CVE-2009-3556
SuSE Security Announcement: SUSE-SA:2010:019 (Google Search)
XForce ISS Database: kernel-qla2xxx-security-bypass(55809)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3889
BugTraq ID: 37019
Common Vulnerability Exposure (CVE) ID: CVE-2009-3939
Common Vulnerability Exposure (CVE) ID: CVE-2009-4020
Common Vulnerability Exposure (CVE) ID: CVE-2009-4021
BugTraq ID: 37069
XForce ISS Database: kernel-fusedirectio-dos(54358)
Common Vulnerability Exposure (CVE) ID: CVE-2009-4138
BugTraq ID: 37339
Common Vulnerability Exposure (CVE) ID: CVE-2009-4141
BugTraq ID: 37806
Common Vulnerability Exposure (CVE) ID: CVE-2009-4272
XForce ISS Database: linux-kernel-routing-dos(55808)
Common Vulnerability Exposure (CVE) ID: CVE-2009-3563
BugTraq ID: 37255
CERT/CC vulnerability note: VU#568372
Debian Security Information: DSA-1948 (Google Search)
HPdes Security Advisory: HPSBUX02639
HPdes Security Advisory: HPSBUX02859
HPdes Security Advisory: SSRT100293
HPdes Security Advisory: SSRT101144
NETBSD Security Advisory: NetBSD-SA2010-005
RedHat Security Advisories: RHSA-2009:1648
RedHat Security Advisories: RHSA-2009:1651
Common Vulnerability Exposure (CVE) ID: CVE-2009-4355
Debian Security Information: DSA-1970 (Google Search)
HPdes Security Advisory: HPSBUX02517
HPdes Security Advisory: SSRT100058
SuSE Security Announcement: SUSE-SA:2010:008 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-2409
Bugtraq: 20101207 VMSA-2010-0019 VMware ESX third party updates for Service Console (Google Search)
Debian Security Information: DSA-1874 (Google Search)
Debian Security Information: DSA-1888 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-0590
BugTraq ID: 34256
Bugtraq: 20090403 rPSA-2009-0057-1 m2crypto openssl openssl-scripts (Google Search)
Debian Security Information: DSA-1763 (Google Search)
FreeBSD Security Advisory: FreeBSD-SA-09:08
HPdes Security Advisory: HPSBMA02447
HPdes Security Advisory: HPSBOV02540
HPdes Security Advisory: HPSBUX02435
HPdes Security Advisory: SSRT090059
HPdes Security Advisory: SSRT090062
NETBSD Security Advisory: NetBSD-SA2009-008
SuSE Security Announcement: SUSE-SR:2009:010 (Google Search)
SuSE Security Announcement: SUSE-SU-2011:0847 (Google Search)
SuSE Security Announcement: openSUSE-SU-2011:0845 (Google Search)
XForce ISS Database: openssl-asn1-stringprintex-dos(49431)
Common Vulnerability Exposure (CVE) ID: CVE-2009-1377
BugTraq ID: 35001
HPdes Security Advisory: HPSBMA02492
HPdes Security Advisory: SSRT100079
NETBSD Security Advisory: NetBSD-SA2009-009
SuSE Security Announcement: SUSE-SR:2009:011 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2009-1378
Common Vulnerability Exposure (CVE) ID: CVE-2009-1379
BugTraq ID: 35138
XForce ISS Database: openssl-dtls1retrievebufferedfragment-dos(50661)
Common Vulnerability Exposure (CVE) ID: CVE-2009-1386
BugTraq ID: 35174
SuSE Security Announcement: SUSE-SR:2009:012 (Google Search)
XForce ISS Database: openssl-changecipherspec-dos(50963)
Common Vulnerability Exposure (CVE) ID: CVE-2009-1387
Common Vulnerability Exposure (CVE) ID: CVE-2009-4212
BugTraq ID: 37749
Debian Security Information: DSA-1969 (Google Search)
HPdes Security Advisory: HPSBOV02682
HPdes Security Advisory: SSRT100495
RedHat Security Advisories: RHSA-2010:0029
Common Vulnerability Exposure (CVE) ID: CVE-2009-1384
BugTraq ID: 35112
Bugtraq: 20110211 VMSA-2011-0003 Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2010-0097
BugTraq ID: 37865
CERT/CC vulnerability note: VU#360341
Debian Security Information: DSA-2054 (Google Search)
HPdes Security Advisory: HPSBUX02519
HPdes Security Advisory: SSRT100004
RedHat Security Advisories: RHSA-2010:0062
XForce ISS Database: bind-dnssecnsec-cache-poisoning(55753)
Common Vulnerability Exposure (CVE) ID: CVE-2010-0290
Common Vulnerability Exposure (CVE) ID: CVE-2009-3736
BugTraq ID: 37128
SuSE Security Announcement: SUSE-SR:2010:006 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2010-0001
Debian Security Information: DSA-1974 (Google Search)
Debian Security Information: DSA-2074 (Google Search)
HPdes Security Advisory: HPSBMA02554
HPdes Security Advisory: SSRT100018
Common Vulnerability Exposure (CVE) ID: CVE-2010-0426
BugTraq ID: 38362
Bugtraq: 20101027 rPSA-2010-0075-1 sudo (Google Search)
Debian Security Information: DSA-2006 (Google Search)
Common Vulnerability Exposure (CVE) ID: CVE-2010-0427
Common Vulnerability Exposure (CVE) ID: CVE-2010-0382
CopyrightCopyright (C) 2012 Greenbone Networks GmbH

Dies ist nur einer von 87302 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.

© 1998-2021 E-Soft Inc. Alle Rechte vorbehalten.