Anfälligkeitssuche        Suche in 172616 CVE Beschreibungen
und 81291 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.103495
Kategorie:VMware Local Security Checks
Titel:VMware ESXi/ESX patches address security issues (VMSA-2012-0011)
Zusammenfassung:The remote ESXi is missing one or more security related Updates from VMSA-2012-0011.
Beschreibung:Summary:
The remote ESXi is missing one or more security related Updates from VMSA-2012-0011.

Vulnerability Insight:
a. VMware Host Checkpoint file memory corruption

Input data is not properly validated when loading Checkpoint files. This may
allow an attacker with the ability to load a specially crafted Checkpoint file
to execute arbitrary code on the host.

b. VMware Virtual Machine Remote Device Denial of Service

A device (e.g. CD-ROM, keyboard) that is available to a virtual machine while
physically connected to a system that does not run the virtual machine is
referred to as a remote device.

Traffic coming from remote virtual devices is incorrectly handled. This may
allow an attacker who is capable of manipulating the traffic from a remote
virtual device to crash the virtual machine.

Affected Software/OS:
ESXi 5.0 without patch ESXi500-201206401-SG

ESXi 4.1 without patch ESXi410-201206401-SG

ESXi 4.0 without patch ESXi400-201206401-SG

ESXi 3.5 without patch ESXe350-201206401-I-SG

ESX 4.1 without patch ESX410-201206401-SG

ESX 4.0 without patch ESX400-201206401-SG

ESX 3.5 without patch ESX350-201206401-SG

Solution:
Apply the missing patch(es).

a. VMware Host Checkpoint file memory corruption

Workaround - None identified

Mitigation - Do not import virtual machines from untrusted sources.

b. VMware Virtual Machine Remote Device Denial of Service

Workaround - None identified

Mitigation - Users need administrative privileges on the virtual machine in
order to attach remote devices. - Do not attach untrusted remote devices to a
virtual machine.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2012-3288
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A17178
Common Vulnerability Exposure (CVE) ID: CVE-2012-3289
CopyrightCopyright (C) 2012 Greenbone Networks GmbH

Dies ist nur einer von 81291 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2020 E-Soft Inc. Alle Rechte vorbehalten.