Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
ESX Server 3.0.0, Patch ESX-1001205: vixe-cron Security Update
Details
|
e6b818cf885d5fd5f93d33b27051df83 |
|
Summary
This patch provides updated service console package vixie-cron fixes. Cron is a standard UNIX daemon that runs specified programs at scheduled times. A denial of service issue was found in the way vixie-cron verified crontab file integrity. A local user with the ability to create a hardlink to /etc/crontab can potentially prevent vixie-cron from executing certain system cron jobs.
Thanks to Raphael Marichez for identifying this issue.
The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2007-1856 to this issue.
Solution
Symptoms
There are no symptoms available for the security fixes.
Impact
Download Instructions
Download and verify the patch bundle as follows:
- Download patch ESX-1001205 from http://www.vmware.com/download/vi/vi3_patches.html.
- Log in to the ESX Server service console as root.
- Create a local depot directory.
# mkdir -p /var/updates
Note: VMware recommends that you use the updates directory.
- Change your working directory to /var/updates.
# cd /var/updates
- Download the tar file into the /var/updates directory.
- Verify the integrity of the downloaded tar file:
# md5sum ESX-1001205.tgz
The md5 checksum output should match the following:
e6b818cf885d5fd5f93d33b27051df83 ESX-1001205.tgz - Extract the compressed tar archive:
# tar -xvzf ESX-1001205.tgz
- Change to the newly created directory, /var/updates/ESX-1001205:
# cd ESX-1001205
Installation Instructions
After you have downloaded and extracted the archive, and if you are in the directory you created above, install the update using the following command:
# esxupdate update
To run esxupdate from a different directory, you must specify the bundle path in the command:
# esxupdate -r file://<directory>/ESX-1001205 update
For example, if the host is called depot:
# esxupdate -r file:///depot/var/updates/ESX-1001205 update
During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below.
# esxupdate -v 10 file://<directory>/ESX-1001205 update
For more information on using esxupdate, refer to the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf.
Keywords
Feedback
- KB Article: 1001205
- Updated: Aug 14, 2009
- Products:
VMware ESX - Product Versions:
VMware ESX 3.0.x

