Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

VMware ESX 4.0, Patch ESX400-201005401-SG: Updates apps, cim, exsupdate, scripts, tools, vmkernel64, uwlibs, kernel, and openssl (1013127)

Details

Release Date: May 27, 2010
 
Download Size:
611.8MB
Download Filename:
ESX400-201005001.zip
md5sum:
ace37cd8d7c6388edcea2798ba8be939
sha1sum:
8fe7312fe74a435e824d879d4f1ff33df25cee78



Product Versions ESX 4.0
Build 256968
Also see KB 1012514.
Patch Classification Security
Host Reboot Required Yes
Virtual Machine Migration or Shutdown Required Yes
PRs Fixed 473524, 489992, 503740, 509882, 514263, 514265, 533662, 535510
Affected Hardware N/A
Affected Software N/A
Modified VIBs Included vmware-esx-apps, vmware-esx-cim, vmware-esx-esxupdate, vmware-esx-scripts, vmware-esx-tools, vmware-esx-uwlibs, vmware-esx-vmkernel64, vmware-esx-vmnixmod, vmware-hostd-esx, kernel, openssl
Related CVE numbers CVE-2009-2695, CVE-2009-2908, CVE-2009-3228, CVE-2009-3286, CVE-2009-3547, CVE-2009-3613, CVE-2009-3612, CVE-2009-3620, CVE-2009-3621, CVE-2009-3726, CVE-2007-4567, CVE-2009-4536, CVE-2009-4537, CVE-2009-4538, CVE-2006-6304, CVE-2009-2910, CVE-2009-3080, CVE-2009-3556, CVE-2009-3889, CVE-2009-3939, CVE-2009-4020, CVE-2009-4021, CVE-2009-4138, CVE-2009-4141, CVE-2009-4272, CVE-2009-2409, CVE-2009-4355, CVE-2009-0590, CVE-2009-1377, CVE-2009-1378, CVE-2009-1379, CVE-2009-1386 CVE-2009-1387

Solution

Summaries and Symptoms

This patch fixes the following security issues:

  • The service console package for OpenSSL is updated to version openssl-0.9.8e-12.el5_4.1. This update fixes two issues:
    • A flaw in the OpenSSL library could cause server applications that call those functions during reload, such as a combination of the Apache HTTP Server, mod_ssl, PHP, and cURL, to consume all available memory, resulting in a denial of service.
      The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-2409 to this issue.
    • Browsers could accept certificates with MD2 hash signatures, even though MD2 is no longer considered a cryptographically strong algorithm. This could make it easier for an attacker to create a malicious certificate that would be treated as trusted by a browser. OpenSSL now disables the use of the MD2 algorithm inside signatures by default. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-4355 to this issue.
    • This update also includes security fixes that were first addressed in version openssl-0.9.8e-12.el5.i386.rpm. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the names CVE-2009-0590, CVE-2009-1377, CVE-2009-1378, CVE-2009-1379, CVE-2009-1386, and CVE-2009-1387 to these issues.

This patch fixes the following issues:

  • ESX 4.0 hosts might stop responding when interrupts are shared between VMkernel and service console. Other symptoms also might be seen: 
    • Network pings to the ESX hosts might fail.
    • Baseboard management controllers (BMC) such as HP Integrated Lights-Out (iLO) console might appear to be in a non-responsive state.
  • The VMware Snapshot Provider service is not listed in the Services panel. The quiesced snapshots do not use VMware Tools VSS components in Windows Server 2008 R2 or Windows 7 operating systems. This issue is seen when the user or backup software performs a quiesced snapshot on virtual machines running on ESX 4.0 hosts.

Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table above.

Patch Download and Installation

See the VMware vCenter Update Manager Administration Guide for instructions on using Update Manager to download and install patches to automatically update ESX 4.0 hosts.

To update ESX 4.0 hosts without using Update Manager, download the patch ZIP file from http://support.vmware.com/selfsupport/download/ and install the bulletin by using esxupdate from the command line of the host. For more information, see the ESX 4 Patch Management Guide.

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 3 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 3 Ratings
Actions
KB: