Mailing List

Name:

Email:

[SingCERT] Third party component updates for VMware vCenter Server, vCenter Update Manager, ESXi and ESX

[ Summary ]

VMware has released an update for vCenter Server 4.1, vCenter Update Manager 4.1, vSphere Hypervisor (ESXi) 4.1, ESXi 4.1 to address several security issues.

 

[ Affected Systems ]

  • vCenter Server 4.1 without Update 1
  • vCenter Update Manager 4.1 without Update 1
  • ESXi 4.1 without patch ESXi410-201101201-SG
  • ESX 4.1 without patch ESX410-201101201-SG1


[ Impact Analysis ]

These issues allow attackers or malicious users to bypass security restrictions, gain knowledge of certain information, execute arbitrary code or cause a denial of service condition.


[ Solution/Workaround ]

Updates are available:

  • VMware vCenter Server 4.1 – Apply Update 1
  • VMware vCenter Update Manager 4.1 – Apply Update 1
  • VMware ESXi 4.1 – Apply patch ESXi410-201101201-SG
  • VMware ESX 4.1 – Apply patch ESX410-201101201-SG


[ Reference ]

http://www.vmware.com/security/advisories/VMSA-2011-0003.html