VMware Security Update for DoS problem among vulnerabilities, kernel source code leaks
VMware, virtualization software manager, has issued a security update for its vSphere API. This resolves a denial-of-service problem in ESX and ESXi. The ESX is a bare metal hypervisor, capable of enterprise level environments, where it doesn’t need a 3rd party operating system to run. Also, quite a few security updates were issued as part of this update.
The patch affects the following releases: VMware ESXi 4.1 without patch ESXi410-201211401-SG and VMware ESX 4.1 without patches ESX410-201211401-SG, ESX410-201211402-SG, ESX410-201211405-SG, and ESX410-201211407-SG.
Read more about the advisory, plus details on how to update.
This security update comes after, just over a week ago, Anonymous hacker “Stun” leaked the source code of ESX. The leak was first found out with a Twitter update, followed by the torrent posted on 1337x.org.
“Which VMware has succeed to ignore and continue producing on same level like it’s buddy Symantec did. Bullshitting people and selling crap. But it’s time for Anonymous finally to deliver,” said “Stun”.
Iain Mulholland, director of platform security for VMware, commented on the story:
It is possible that more related files will be posted in the future. We take customer security seriously and have engaged our VMware Security Response Center to thoroughly investigate.
Ensuring customer security is our top priority. As a matter of best practices with respect to security, VMware strongly encourages all customers to apply the latest product updates and security patches made available for their specific environment.
This also apparently is linked back to an April 2012 incident, where information was leaked also.
The kernel is apparently dated back to between 1998-2004, the years of which the kernel for VMware products was developed.
Users are encouraged to update their products with the latest product updates and security patches.
Tags: 4.1, Anonymous (group), Bare metal, Enterprise, ESX, ESXi, Hypervisor, Iain Mulholland, Patch (computing), Services Console, Virtual machine monitor, VMware, vSphere API
About Jay Pfoutz
Full time computer security consultantOne response to “VMware Security Update for DoS problem among vulnerabilities, kernel source code leaks”
Recent Posts
Topics
Popular Tags
Editor’s Twitter
- What are you dreaming of these days? 23 hours ago
- Leadership is the single best quality to your business lifestyle. Don't quit being a leader, being the example, and making a difference. 1 day ago
- Guest Post: Strategically Manage Business Expenses to Avoid Incurring Debt: By Patricia Garner (G+)Guest Write... bit.ly/10VVzc6 2 days ago
- Software Company Acquisitions Produce Many Insecurities: You may think these software company acquisitions are... bit.ly/143RJMZ 4 days ago
- Small Business Consulting Should Be at your Fingertips: I'm sure you know what a consultant is. The dictionary... bit.ly/17rasWF 5 days ago
Blogroll
- Fortinet FortiBlog
- Crowdstrike Blog
- SANS Securing The Human Blog
- US-CERT Computer Emergency Response Team
- SecuraGeek Forums
- Spyware Sucks Blog
- Websense Security Labs Blog
- Cyveillance Blog
- We Live Security (ESET)
- MSNBC Red Tape Blog
- Malwarebytes Unpacked
- AVG Blogs
- hpHosts Blog
- F-Secure Weblog
- Google Online Security Blog
- Security Battlefield with George Kurtz
- Skidlist
- Bleeping Computer Virus, Spyware, & Malware Removal Guides
- Bart Blaze's Security Blog
- Schneier on Security
- TrendLabs Malware Blog
- Slug Analysis Lab
- Security Affairs
- mxlab Blog
- DSL Reports Sec. Forum
- Microsoft Malware Protection Center Blog
- RKHunter Sec/Mal Blog
- ThreatMetrix Frauds & Ends Blog
- Wired ThreatLevel Blog
- ThreatPost
- SecureList Blog by Kaspersky
- SANS Internet Storm Center
- Bill Mullins Weblog
- S!Ri.URZ Blog
- Naked Security
- Web of Trust Blog
- FireEye Blog
- Lavasoft Security Blog
- DHS Daily Report (Homeland-Sec)
- Lookout Mobile Security Blog
- Dancho Danchev's blog
- TaoSecurity Blog
- Unmask Parasites
- Stop Badware Blog
- Arbor Networks
- evilfantasy's Blog
- Webroot Blog
- SWW Blog
- Dejan Kosutic's ISO 27001/22301 Standards
- Kafeine's Malware Don't Need Coffee

Reblogged this on Yury Chemerkin and commented:
Add your thoughts here… (optional)