Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
ESX Server 3.0.1, Patch ESX-1002963; Fix for OpenPegasus Management Server
Details
|
Download Now Download Size: 15.0 MB Download Filename: ESX-1002963.tgz md5sum: c1b9468850f4d7a0a97bb445e5b53885 |
|
Summary
The patch fixes the following security issues:
-
Alexander Sotirov of VMware discovered a buffer overflow vulnerability in the OpenPegasus Management server. This flaw can be exploited by a malicious remote user to gain root access to the service console.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-5360 to this issue. - Fixes a deadlock issue in recursive provider calls.
Solution
Symptoms
Deployment Considerations
-
After installing this patch, restart the pegasus service using the command service pegasus restart . If you do not use pegasus and want to keep the service off, you don't have to do anything.
-
Applying this patch affects the CIMOM server running in the service console.
Download Instructions
Download and verify the patch bundle as follows:
1. Download patch ESX-1002963 from http://www.vmware.com/download/vi/vi3_patches.html .
2. Log in to the ESX Server service console as root.
3. Create a local depot directory.
# mkdir -p /var/updates
Note: VMware recommends that you use the updates directory.
4. Change your working directory to /var/updates .
# cd /var/updates
5. Download the tar file into the /var/updates directory.
The md5 checksum output should match the following:
c1b9468850f4d7a0a97bb445e5b53885 ESX-1002963.tgz
7. Extract the compressed tar archive:
# tar -xvzf ESX-1002963.tgz
8. Change to the newly created directory, /var/updates/ESX-1002963:
# cd ESX-1002963
Installation Instructions
After you download and extract the archive, and if you are in the directory that you previously created, use the following command to install the update:
# esxupdate update
To run esxupdate from a different directory, you must specify the bundle path in the command:
# esxupdate -r file://<directory>/ESX-1002963 update
For example, if the host is called depot:
# esxupdate -r file:///depot/var/updates/ESX-1002963 update
During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below.
# esxupdate -v 10 file://<directory>/ESX-1002963 update
For more information how to use esxupdate, see the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf .
Keywords
Feedback
- KB Article: 1002963
- Updated: Aug 14, 2009
- Products:
VMware ESX - Product Versions:
VMware ESX 3.0.x

