Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

VMware ESX 3.5 Update 4, Patch ESX350-200903227-UG: Updates Libxml2 (1008093)

Details

Release Date: March 30, 2009

 

Download Size:
1.1MB
Download Filename:
ESX350-200903227-UG.zip
md5sum:
af9e30166e4b92a13f29b759102292c7

Product Versions ESX 3.5 Update 4
Build 153875
Also see KB 1001179.
Patch Classification General
Supersedes
ESX350-200811405-SG
ESX350-200901410-SG
Requires None
Virtual Machine Migration or Shutdown Required No
Host Reboot Required No
PRs Fixed 350150
Affected Hardware N/A
Affected Software N/A
RPMs Included libxml2
libxml2-python
Related CVE numbers CVE-2008-4309


Solution

Summaries and Symptoms

This patch incorporates the changes from patch ESX350-200901410-SG: Security Update for libxml2 in the Service Console (1006660) into ESX 3.5 Update 4.

An integer overflow flaw causing a heap-based buffer overflow was found in the libxml2 XML parser. If an application linked against libxml2 processed untrusted, malformed XML content, it could cause the application to crash or, possibly, execute arbitrary code.

The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2008-4226 to this issue.

A denial of service flaw was discovered in the libxml2 XML parser. If an application linked against libxml2 processed untrusted, malformed XML content, it could cause the application to enter an infinite loop.

The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2008-4225 to this issue.


Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table, above.

Patch Download and Installation

See the VMware Update Manager Administration Guide for instructions on using Update Manager to download and install patches to automatically update ESX Server 3.5 hosts.

To update ESX Server 3.5 hosts when not using Update Manager, download the most recent patch bundle from http://www.vmware.com/download/vi/vi3_patches_35.html and install the bundle using esxupdate from the command line of the host. For more information, see the ESX Server 3 Patch Management Guide.

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 1 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 1 Ratings
Actions
KB: