Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

ESX Server 3.0.1, Patch ESX-1005108: Fixes for Replacing msvcrt.dll,VMware Tools Installed on Solaris 10 U5,VMware Tools Upgrade from ESX Server 3.0.x GA to ESX Server 3.0.x;Third Party Library libpng Updated to 1.2.29;LVM Allows Same Extent to Be Added (1005108)

Details

Release Date: 08/28/08
Document Last Updated: 08/28/08
 
aabc873d978f023c929ccd9a54588ea5


Product Versions
ESX Server 3.0.1
Patch Classification
Security
Supersedes
Virtual Machine Migration or Reboot Required
Yes
ESX Server Host Reboot Required
Yes
PRs Fixed
131843, 254388, 273899, 238299, 281597, 299409, 301905, 169339, 252374
Affected Hardware
N/A
Affected Software
VMware Tools, libpng, Solaris 10 U5 virtual machine, Red Hat Enterprise Linux 4.7 Beta guest operating system
RPMs Included
VMware-esx-tools,VMware-esx-vmx, VMware-esx-vmkernel, VMware-esx-apps
Related CVE numbers
CVE-2007-5269

Summary

This patch fixes the following issues:

  • An older version of msvcrt.dll  might replace a higher version of msvcrt.dll during VMware Tools upgrade. This fix addresses the issue and replaces the msvcrt.dll only if a higher version is not present.

  • Suspend and resume operations on virtual machines might cause the virtual machines to stop responding.

  • When users upgrade from GA to patch installations of ESX Server 3.0.x, the VMware Tools package is not upgraded.

  • During a VMotion, the destination virtual machine might stop responding when data is not received from source machine.

  • Several flaws were discovered in the way third party library  libpng handled various PNG image chunks. An attacker could create a carefully crafted PNG image file in such a way that it causes an application linked with libpng to crash when the file is manipulated. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the name CVE-2007-5269 to the security issue fixed in this update. To complete the fix, install ESX-1005108, ESX-1005111, and ESX-1005112.

  • After installing VMware Tools on a Solaris 10 U5 virtual machine on ESX Server 3.0.1, the mouse cursor cannot be moved out of the virtual machine without pressing Ctrl+Alt keys.

  • Installation of Red Hat Enterprise Linux 4.7 Beta guest operating system in graphical mode on a virtual machine fails due to any movement of the mouse cursor.

  • One ESX Server host can add the same extent more than once to a volume created by another ESX Server host.

Solution

Symptoms

The following symptoms might occur without this patch:
  • Panic and unrecoverable error messages may be logged in the /vmware/log file during suspend and resume operations on virtual machines.
  • During a VMware Tools upgrade, older files are not replaced.
  • Virtual machine core dumps are generated in the virtual machine's directory on the VMFS volume during VMotion.
  • When installing Red Hat Enterprise Linux 4.7 Beta guest operating system in graphical mode on a virtual machine, moving mouse cursor causes error messages and the installation fails.

Deployment Considerations

To address the libpng issue, you must install ESX-1005108, ESX-1005111, and ESX-1005112 to complete the fix.

Download Instructions

Download and verify the patch bundle as follows:

  1. Download patch ESX-1005108 from http://www.vmware.com/download/vi/vi3_patches.html.

  2. Log in to the ESX Server service console as root.

  3. Create a local depot directory.

    # mkdir -p /var/updates

    Note: VMware recommends that you use the updates directory.

  4. Change your working directory to /var/updates.

    # cd /var/updates

  5. Download the tar file into the /var/updates directory.

  6. Verify the integrity of the downloaded tar file:

    # md5sum ESX-1005108.tgz

    The md5 checksum output should match the following:

    aabc873d978f023c929ccd9a54588ea5 ESX-1005108.tgz

  7. Extract the compressed tar archive:

    # tar -xvzf ESX-1005108.tgz

  8. Change to the newly created directory, /var/updates/ESX-1005108:

    # cd ESX-1005108

Installation Instructions

Note: All virtual machines on the host must be either shut down or migrated using VMotion before applying the patch.  A reboot of the ESX Server host is required after applying this patch.
 
After you download and extract the archive, and if you are in the directory that you previously created, use the following command to install the update:

# esxupdate update

To run esxupdate from a different directory, you must specify the bundle path in the command:

# esxupdate -r file://<directory>/ESX-1005108 update

For example, if the host is called depot:

# esxupdate -r file:///depot/var/updates/ESX-1005108 update

During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown, below.

# esxupdate -v 10 file://<directory>/ESX-1005108 update

For more information on how to use esxupdate, see the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf.

Keywords

esxpatch;esx301

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 0 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 0 Ratings
Actions
KB: