
Search the Knowledge Base: |
Search the Knowledge Base: |
|
75aa49eecec2e84eb41a4c26683d4c7a |
|
Updated Bind package for the service console fixes a flaw with the way ISC BIND processed certain DNS query responses. ISC BIND (Berkeley Internet Name Domain) is an implementation of the DNS (Domain Name System) protocols. Under some circumstances, a malicious remote user could launch a Denial-of-Service attack on ESX Server hosts that had enabled DNSSEC validation.
There are no symptoms available for this security fix.
Download and verify the patch bundle as follows:
# mkdir -p /var/updates
Note: VMware recommends that you use the updates directory.
# cd /var/updates
# md5sumESX-1001725.tgz
The md5 checksum output should match the following:
75aa49eecec2e84eb41a4c26683d4c7a ESX-1001725.tgz
# tar -xvzfESX-1001725.tgz
# cdESX-1001725
After you have downloaded and extracted the archive, and if you are in the directory you created above, install the update using the following command:
# esxupdate update
If you want to run esxupdate from a different directory, you must specify the bundle path in the command:
# esxupdate -r file://<directory>/ESX-1001725 update
For example, if the host is called depot:
# esxupdate -r file:///depot/var/updates/ESX-1001725 update
During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below.
# esxupdate -v 10 file://<directory>/ESX-1001725 update
For more information on using esxupdate, refer to the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf.