Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

VMware ESX 4.0, Patch ESX400-200906405-SG: Updates krb5 and pam_krb5

Details

Release Date: July 9, 2009

Download Size:
396.3 MB
Download Filename:
ESX400-200906001.zip
md5sum:
cab549922f3429b236633c0e81351cde
sha1sum:
aff76554ec5ee3c915eb4eac02e62c131163059a

Product Versions ESX 4.0
Build 175625
Also see KB 1012514.
Patch Classification Security
Host Reboot Required Yes
Virtual Machine Migration or Shutdown Required Yes
PRs Fixed 396133
Affected Hardware N/A
Affected Software MIT Kerberos 5 before version 1.6.4, Service Console package krb5, Service Console package pam_krb5
VIBs Included krb5-libs
krb5-workstation
pam_krb5
Related CVE numbers CVE-2009-0844, CVE-2009-0845, CVE-2009-0846

Solution

Summaries and Symptoms

Issues fixed in this patch (and their relevant symptoms, if applicable) include:

  • Service Console package krb5 has been updated to version krb5-1.6.1-31. This fixes the following issues:

    Kerberos versions 5 1.5 through 1.6.3 might allow remote attackers to cause a denial of service and possibly obtain sensitive information by using a crafted length value that triggers a buffer over-read. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-0844 to this issue.

    MIT Kerberos versions 5 1.5 through 1.6.3 might allow remote attackers to cause a denial of service by using invalid ContextFlags data in the reqFlags field in a negTokenInit token. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-0845 to this issue.

    MIT Kerberos 5 before version 1.6.4 might allow remote attackers to cause a denial of service or possibly execute arbitrary code by using vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-0846 to this issue.

    Service Console package pam_krb5 has been upgraded to pam_krb5-2.2.14-10. For details on the issues that this upgrade addresses, refer to the Red Hat advisory at https://rhn.redhat.com/errata/RHBA-2009-0135.html.

Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table, above.

Patch Download and Installation

See the VMware vCenter Update Manager Administration Guide for instructions on using Update Manager to download and install patches to automatically update ESX 4.0 hosts.

To update ESX 4.0 hosts when not using Update Manager, download the patch zip file from http://support.vmware.com/selfsupport/download/ and install the bulletin using esxupdate from the command line of the host. For more information, see the ESX 4 Patch Management Guide.

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback


Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
Actions