Knowledge Base

|
ESX Server 3.0.1, Patch ESX-1006030: Service Console Update to Net-SNMP (1006030)
Details
|
3a52550ca6c958fc09af8ca4484aa6c9 |
|
Summary
-
A flaw was found in the way Net-SNMP checks a SNMP version 3 packet's Keyed-Hash Message Authentication Code (HMAC). The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2008-0960 to this issue.
-
A buffer overflow was found in the Perl bindings for Net-SNMP. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2008-2292 to this issue.
Solution
Symptoms
Deployment Considerations
Download Instructions
Download and verify the patch bundle as follows:
- Download patch ESX-1006030 from http://www.vmware.com/download/vi/vi3_patches.html.
- Log in to the ESX Server service console as root.
- Create a local depot directory.
# mkdir -p /var/updates
Note: VMware recommends that you use the updates directory.
- Change your working directory to /var/updates.
# cd /var/updates
- Download the tar file into the /var/updates directory.
- Verify the integrity of the downloaded tar file:
# md5sum ESX-1006030.tgz
The md5 checksum output should match the following:
3a52550ca6c958fc09af8ca4484aa6c9 ESX-1006030.tgz
- Extract the compressed tar archive:
# tar -xvzf ESX-1006030.tgz
- Change to the newly created directory, /var/updates/ESX-1006030:
# cd ESX-1006030
Installation Instructions
After you download and extract the archive, and if you are in the directory that you previously created, use the following command to install the update:
# esxupdate update
To run esxupdate from a different directory, you must specify the bundle path in the command:
# esxupdate -r file://<directory>/ESX-1006030 update
For example, if the host is called depot:
# esxupdate -r file:///depot/var/updates/ESX-1006030 update
During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown, below.
# esxupdate -v 10 file://<directory>/ESX-1006030 update
For more information on how to use esxupdate, see the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf.
Keywords
Request a Product Feature
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

