BleepingComputer.com: Vmware - Critical Security Update

Jump to content

Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Vmware - Critical Security Update System Admins should apply this quickly

#1 User is offline   harrywaldron 

  • Security Reporter
  • PipPipPipPip
  • Find Topics
  • Group: Members
  • Posts: 509
  • Joined: 10-April 04
  • Gender:Male
  • Location:Roanoke, Virginia

  Posted 26 December 2005 - 09:07 AM

Quote

Technical Description:
Advisory ID : FrSIRT/ADV-2005-3084
Remotely Exploitable : Yes
Locally Exploitable : Yes
Release Date : 2005-12-24

A vulnerability has been identified in VMware ESX Server, which may be exploited by attackers to inject malicious HTML code. This flaw is due to an input validation error in the VMware Management Interface that does not properly validate certain parameters, which may be exploited by attackers to cause arbitrary scripting code to be executed by the user's browser in the security context of an affected Web site.

Affected Products: WMware ESX Server 2.0.x, 2.1.x, 2.5.x

Solution: Apply latest VmWare Patches
http://www.vmware.com/support/kb/enduser/s...hp?p_faqid=2001


Sharing as an FYI for those using VMware for server consolidation and management.

VMware - Critical Security Update should be applied quickly
http://www.frsirt.com/english/advisories/2005/3084

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users