copyright | disclaimer | privacy | contact  
Australia's Leading Computer Emergency Response Team
 
Search this site

 
On this site

 > HOME
 > About AusCERT
 > Membership
 > Contact Us
 > PKI Services
 > Training
 > Publications
 > Sec. Bulletins
 > Conferences
 > News & Media
 > Services
 > Web Log
 > Site Map
 > Site Help
 > Member login





 

ESB-2010.0486.2 - UPDATE [VMware ESX] VMWare: Multiple vulnerabilities

Date: 25 June 2010
References: ESB-2010.0224.3  ESB-2010.0484  

Click here for printable version
Click here for PGP verifiable version
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                              ESB-2010.0486.2
       ESXi update for ntp and ESX Console OS (COS) updates for COS
               kernel, openssl, krb5, gcc, bind, gzip, sudo
                               25 June 2010

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:          ntp
                  ESX Console OS (COS) kernel
                  openssl
                  krb5
                  gcc
                  bind
                  gzip
                  sudo
Publisher:        VMWare
Operating System: VMWare ESX Server
Impact/Access:    Execute Arbitrary Code/Commands -- Remote/Unauthenticated      
                  Increased Privileges            -- Existing Account            
                  Denial of Service               -- Remote/Unauthenticated      
                  Access Confidential Data        -- Remote/Unauthenticated      
                  Unauthorised Access             -- Remote with User Interaction
Resolution:       Patch/Upgrade
CVE Names:        CVE-2010-0427 CVE-2010-0426 CVE-2010-0382
                  CVE-2010-0290 CVE-2010-0097 CVE-2010-0001
                  CVE-2009-4538 CVE-2009-4537 CVE-2009-4536
                  CVE-2009-4355 CVE-2009-4272 CVE-2009-4212
                  CVE-2009-4141 CVE-2009-4138 CVE-2009-4021
                  CVE-2009-4020 CVE-2009-3939 CVE-2009-3889
                  CVE-2009-3736 CVE-2009-3726 CVE-2009-3621
                  CVE-2009-3620 CVE-2009-3613 CVE-2009-3612
                  CVE-2009-3563 CVE-2009-3556 CVE-2009-3547
                  CVE-2009-3286 CVE-2009-3228 CVE-2009-3080
                  CVE-2009-2910 CVE-2009-2908 CVE-2009-2695
                  CVE-2009-2409 CVE-2009-1387 CVE-2009-1386
                  CVE-2009-1384 CVE-2009-1379 CVE-2009-1378
                  CVE-2009-1377 CVE-2009-0590 CVE-2007-4567
                  CVE-2006-6304  

Reference:        ESB-2010.0484
                  ESB-2010.0224

Revision History: June 25 2010: Updated security advisory after release of 
                                patches for ESX 3.5
                  May  31 2010: Initial Release

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - ------------------------------------------------------------------------
                   VMware Security Advisory

Advisory ID:       VMSA-2010-0009.1
Synopsis:          ESXi ntp and ESX Service Console third party updates
Issue date:        2010-05-27
Updated on:        2010-06-24
CVE numbers:       CVE-2009-2695 CVE-2009-2908 CVE-2009-3228
                   CVE-2009-3286 CVE-2009-3547 CVE-2009-3613
                   CVE-2009-3612 CVE-2009-3620 CVE-2009-3621
                   CVE-2009-3726 CVE-2007-4567 CVE-2009-4536
                   CVE-2009-4537 CVE-2009-4538 CVE-2006-6304
                   CVE-2009-2910 CVE-2009-3080 CVE-2009-3556
                   CVE-2009-3889 CVE-2009-3939 CVE-2009-4020
                   CVE-2009-4021 CVE-2009-4138 CVE-2009-4141
                   CVE-2009-4272 CVE-2009-3563 CVE-2009-4355
                   CVE-2009-2409 CVE-2009-0590 CVE-2009-1377
                   CVE-2009-1378 CVE-2009-1379 CVE-2009-1386
                   CVE-2009-1387 CVE-2009-4212 CVE-2009-1384
                   CVE-2010-0097 CVE-2010-0290 CVE-2009-3736
                   CVE-2010-0001 CVE-2010-0426 CVE-2010-0427
                   CVE-2010-0382
- - ------------------------------------------------------------------------

1. Summary

   ESXi update for ntp and ESX Console OS (COS) updates for COS
   kernel, openssl, krb5, gcc, bind, gzip, sudo.

2. Relevant releases

   VMware ESXi 4.0.0 without patch ESXi400-201005401-SG

   VMware ESX 4.0.0 without patches ESX400-201005401-SG,
   ESX400-201005406-SG, ESX400-201005408-SG, ESX400-201005407-SG,
   ESX400-201005405-SG, ESX400-201005409-SG

   VMware ESX 3.5 without patches ESX350-201006408-SG,
   ESX350-201006405-SG, ESX350-201006406-SG

3. Problem Description

 a. Service Console update for COS kernel

    Updated COS package "kernel" addresses the security issues that are
    fixed through versions 2.6.18-164.11.1.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2009-2695, CVE-2009-2908, CVE-2009-3228,
    CVE-2009-3286, CVE-2009-3547, CVE-2009-3613 to the security issues
    fixed in kernel 2.6.18-164.6.1

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2009-3612, CVE-2009-3620, CVE-2009-3621,
    CVE-2009-3726 to the security issues fixed in kernel 2.6.18-164.9.1.

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2007-4567, CVE-2009-4536, CVE-2009-4537,
    CVE-2009-4538 to the security issues fixed in kernel 2.6.18-164.10.1

    The Common Vulnerabilities and Exposures project (cve.mitre.org)
    has assigned the names CVE-2006-6304, CVE-2009-2910, CVE-2009-3080,
    CVE-2009-3556, CVE-2009-3889, CVE-2009-3939, CVE-2009-4020,
    CVE-2009-4021, CVE-2009-4138, CVE-2009-4141, and CVE-2009-4272 to
    the security issues fixed in kernel 2.6.18-164.11.1.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005401-SG
    ESX            3.5       ESX      not applicable
    ESX            3.0.3     ESX      not applicable
    ESX            2.5.5     ESX      not applicable

    vMA            4.0       RHEL5    affected, patch pending

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 b. ESXi userworld update for ntp

    The Network Time Protocol (NTP) is used to synchronize the time of
    a computer client or server to another server or reference time
    source.

    A vulnerability in ntpd could allow a remote attacker to cause a
    denial of service (CPU and bandwidth consumption) by using
    MODE_PRIVATE to send a spoofed (1) request or (2) response packet
    that triggers a continuous exchange of MODE_PRIVATE error responses
    between two NTP daemons.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-3563 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           4.0       ESXi     ESXi400-201005401-SG
    ESXi           3.5       ESXi     ESXe350-201006401-I-SG

    ESX            any       ESX      not applicable

    vMA            any       RHEL5    not applicable

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 c. Service Console package openssl updated to 0.9.8e-12.el5_4.1

    OpenSSL is a toolkit implementing SSL v2/v3 and TLS protocols with
    full-strength cryptography world-wide.

    A memory leak in the zlib could allow a remote attacker to cause a
    denial of service (memory consumption) via vectors that trigger
    incorrect calls to the CRYPTO_cleanup_all_ex_data function.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-4355 to this issue.

    A vulnerability was discovered which may allow remote attackers to
    spoof certificates by using MD2 design flaws to generate a hash
    collision in less than brute-force time. NOTE: the scope of this
    issue is currently limited because the amount of computation
    required is still large.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-2409 to this issue.

    This update also includes security fixes that were first addressed
    in version openssl-0.9.8e-12.el5.i386.rpm.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the names CVE-2009-0590, CVE-2009-1377, CVE-2009-1378,
    CVE-2009-1379, CVE-2009-1386 and CVE-2009-1387 to these issues.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005401-SG
    ESX            3.5       ESX      not applicable
    ESX            3.0.3     ESX      not applicable
    ESX            2.5.5     ESX      not applicable

    vMA            4.0       RHEL5    affected, patch pending**

  *  hosted products are VMware Workstation, Player, ACE, Server, Fusion.
  ** see VMSA-2010-0004

 d. Service Console update for krb5 to 1.6.1-36.el5_4.1 and pam_krb5 to
    2.2.14-15.

    Kerberos is a network authentication protocol. It is designed to
    provide strong authentication for client/server applications by
    using secret-key cryptography.

    Multiple integer underflows in the AES and RC4 functionality in the
    crypto library could allow remote attackers to cause a denial of
    service (daemon crash) or possibly execute arbitrary code by
    providing ciphertext with a length that is too short to be valid.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-4212 to this issue.

    The service console package for pam_krb5 is updated to version
    pam_krb5-2.2.14-15. This update fixes a flaw found in pam_krb5. In
    some non-default configurations (specifically, where pam_krb5 would
    be the first module to prompt for a password), a remote attacker
    could use this flaw to recognize valid usernames, which would aid a
    dictionary-based password guess attack.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-1384 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005406-SG
    ESX            3.5       ESX      ESX350-201006408-SG
    ESX            3.0.3     ESX      affected, patch pending
    ESX            2.5.5     ESX      affected, patch pending

    vMA            4.0       RHEL5    affected, patch pending

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 e. Service Console package bind updated to 9.3.6-4.P1.el5_4.2

    BIND (Berkeley Internet Name Daemon) is by far the most widely used
    Domain Name System (DNS) software on the Internet.

    A vulnerability was discovered which could allow remote attacker to
    add the Authenticated Data (AD) flag to a forged NXDOMAIN response
    for an existing domain.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-0097 to this issue.

    A vulnerability was discovered which could allow remote attackers
    to conduct DNS cache poisoning attacks by receiving a recursive
    client query and sending a response that contains CNAME or DNAME
    records, which do not have the intended validation before caching.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-0290 to this issue.

    A vulnerability was found in the way that bind handles out-of-
    bailiwick data accompanying a secure response without re-fetching
    from the original source, which could allow remote attackers to
    have an unspecified impact via a crafted response.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-0382 to this issue.

    NOTE: ESX does not use the BIND name service daemon by default.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005408-SG
    ESX            3.5       ESX      not applicable
    ESX            3.0.3     ESX      not applicable
    ESX            2.5.5     ESX      not applicable

    vMA            4.0       RHEL5    affected, patch pending

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 f. Service Console package gcc updated to 3.2.3-60

    The GNU Compiler Collection includes front ends for C, C++,
    Objective-C, Fortran, Java, and Ada, as well as libraries for these
    languages

    GNU Libtool's ltdl.c attempts to open .la library files in the
    current working directory.  This could allow a local user to gain
    privileges via a Trojan horse file.  The GNU C Compiler collection
    (gcc) provided in ESX contains a statically linked version of the
    vulnerable code, and is being replaced.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2009-3736 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not applicable

    ESX            4.0       ESX      ESX400-201005407-SG
    ESX            3.5       ESX      ESX350-201006405-SG
    ESX            3.0.3     ESX      affected, patch pending
    ESX            2.5.5     ESX      affected, patch pending

    vMA            4.0       RHEL5    affected, patch pending

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 g. Service Console package gzip update to 1.3.3-15.rhel3

    gzip is a software application used for file compression

    An integer underflow in gzip's unlzw function on 64-bit platforms
    may allow a remote attacker to trigger an array index error
    leading to a denial of service (application crash) or possibly
    execute arbitrary code via a crafted LZW compressed file.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-0001 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005405-SG
    ESX            3.5       ESX      ESX350-201006406-SG
    ESX            3.0.3     ESX      affected, patch pending
    ESX            2.5.5     ESX      affected, patch pending

    vMA            4.0       RHEL5    affected, patch pending

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

 h. Service Console package sudo updated to 1.6.9p17-6.el5_4

    Sudo (su "do") allows a system administrator to delegate authority
    to give certain users (or groups of users) the ability to run some
    (or all) commands as root or another user while providing an audit
    trail of the commands and their arguments.

    When a pseudo-command is enabled, sudo permits a match between the
    name of the pseudo-command and the name of an executable file in an
    arbitrary directory, which allows local users to gain privileges
    via a crafted executable file.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-0426 to this issue.

    When the runas_default option is used, sudo does not properly set
    group memberships, which allows local users to gain privileges via
    a sudo command.

    The Common Vulnerabilities and Exposures Project (cve.mitre.org)
    has assigned the name CVE-2010-0427 to this issue.

    Column 4 of the following table lists the action required to
    remediate the vulnerability in each release, if a solution is
    available.

    VMware         Product   Running  Replace with/
    Product        Version   on       Apply Patch
    =============  ========  =======  =================
    VirtualCenter  any       Windows  not affected

    hosted *       any       any      not affected

    ESXi           any       ESXi     not affected

    ESX            4.0       ESX      ESX400-201005409-SG
    ESX            3.5       ESX      not applicable
    ESX            3.0.3     ESX      not applicable
    ESX            2.5.5     ESX      not applicable

    vMA            4.0       RHEL5    affected, patch pending

  * hosted products are VMware Workstation, Player, ACE, Server, Fusion.

4. Solution

   Please review the patch/release notes for your product and version
   and verify the md5sum of your downloaded file.

   ESXi 4.0
   --------
   http://bit.ly/bjWeCV
   md5sum: f2295659befeb4da2542811d3c3d5467
   sha1sum: a0e5a9211f0faf5caadbd3c3a1fd7b421eb0f473
   http://kb.vmware.com/kb/1021041

   Note  ESXi400-201005001 contains the following security fix:
   ESXi400-201005401-SG (ntp).

   ESX 4.0
   -------
   http://bit.ly/aqTCqn
   md5sum: ace37cd8d7c6388edcea2798ba8be939
   sha1sum: 8fe7312fe74a435e824d879d4f1ff33df25cee78
   http://kb.vmware.com/kb/1013127

   Note ESX400-201005001 contains the following security bulletins
   ESX400-201005404-SG (ntp), ESX400-201005405-SG (gzip),
   ESX400-201005408-SG (bind), ESX400-201005401-SG (kernel, openssl),
   ESX400-201005406-SG (krb5, pam_krb5), ESX400-201005402-SG (JRE),
   ESX400-201005403-SG (expat), ESX400-201005409-SG (sudo),
   ESX400-201005407-SG (gcc).

   ESXi 3.5
   --------
   ESXe350-201006401-I-SG (ntp)
   http://download3.vmware.com/software/vi/ESXe350-201006401-O-SG.zip
   md5sum: 13e8110783b09ff40cd21f35cfd930f9
   http://kb.vmware.com/kb/1020052

   Note: ESXe350-201006401-O-SG contains the bundle with the security fix
         ESXe350-201006401-I-SG

   To install an individual bulletin use esxupdate with the -b option.
   esxupdate --bundle ESXe350-201006401-O-SG -b ESXe350-201006401-I-SG

   ESX 3.5
   -------
   ESX350-201006408-SG (krb5)
   http://download3.vmware.com/software/vi/ESX350-201006408-SG.zip
   md5sum: a0da0fd9a8e2a9896870cd85360b6be3
   http://kb.vmware.com/kb/1020172

   ESX350-201006405-SG (gcc)
   http://download3.vmware.com/software/vi/ESX350-201006405-SG.zip
   md5sum: e8267f2fca27e2e219f46ff8f9ebba66
   http://kb.vmware.com/kb/1020169

   ESX350-201006406-SG (gzip)
   http://download3.vmware.com/software/vi/ESX350-201006406-SG.zip
   md5sum: 21845a6c5c123b250e6855d41e195add
   http://kb.vmware.com/kb/1020170

5. References

   CVE numbers
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2695
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2908
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3228
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3286
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3547
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3613
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3612
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3620
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3621
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3726
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-4567
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4536
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4537
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4538
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6304
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2910
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3080
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3556
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3889
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3939
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4020
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4021
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4138
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4141
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4272
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3563
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4355
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2409
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0590
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1377
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1378
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1379
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1386
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1387
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-4212
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-1384
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0097
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0290
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3736
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0001
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0426
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0427
   http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-0382

- - ------------------------------------------------------------------------

6. Change log

2010-05-27  VMSA-2010-0009
Initial security advisory after release of patch 06 bulletins for ESX
4.0 on 2010-05-27
2010-06-24  VMSA-2010-0009.1
Updated security advisory after release of patches for ESX 3.5
on 2010-06-24.

- - -----------------------------------------------------------------------
7. Contact

E-mail list for product security notifications and announcements:
http://lists.vmware.com/cgi-bin/mailman/listinfo/security-announce

This Security Advisory is posted to the following lists:

  * security-announce at lists.vmware.com
  * bugtraq at securityfocus.com
  * full-disclosure at lists.grok.org.uk

E-mail:  security at vmware.com
PGP key at: http://kb.vmware.com/kb/1055

VMware Security Center
http://www.vmware.com/security

VMware security response policy
http://www.vmware.com/support/policies/security_response.html

General support life cycle policy
http://www.vmware.com/support/policies/eos.html

VMware Infrastructure support life cycle policy
http://www.vmware.com/support/policies/eos_vi.html

Copyright 2010 VMware Inc.  All rights reserved.


- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.10 (MingW32)

iEYEARECAAYFAkwkQy4ACgkQS2KysvBH1xn5TwCfbgC6JAXoBueUmPeb0QGa5FmB
2OYAnRAK9ANPlQjULtfvJCkU0ChM04W/
=/X+R
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

If you believe that your computer system has been compromised or attacked in 
any way, we encourage you to let us know by completing the secure National IT 
Incident Reporting Form at:

        http://www.auscert.org.au/render.html?it=3192

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iD8DBQFMJEyE/iFOrG6YcBERAnX/AKDM7ZoX8tTxBylw3cI8Y5GoMsvSvQCfTLa7
+GdCyWgrEG73XtExu1TwJ4I=
=PCdf
-----END PGP SIGNATURE-----