Knowledge Base

|
Remediation of CVE-2009-3731 on VMware Server 2.0.2 (1016594)
Details
This KB provides remediation for a security vulnerability that is present in VMware Server 2.0.2. This issue is documented in http://www.vmware.com/security/advisories/VMSA-2009-0017.html and is identified by CVE-2009-3731.
Vmware Server 1.0.x is not affected by this issue.
Solution
These steps remediate CVE-2009-3731 on Server 2.0.2 running on Windows and running on Linux:
-
Download the zip archive linked from this KB article.
Filename: VMwareServer202-CVE-2009-3731.zip
Download location: http://download3.vmware.com/software/vi/VMwareServer202-CVE-2009-3731.zip
MD5: c1f2fb4535acb0728d6de6b971e449de
SHA1: 018d41d4fbc0586d8f6a4e00eba05a454b4d8f26
Note: Read the Acceptance of Terms Notice, below, before downloading. -
Verify that the MD5 or SHA1 sum of the downloaded file matches the value listed in the step above.
-
Unzip the archive.
-
Backup the following files
file
location
index.html
[root]
api.htm
[root]\wwhelp\wwhimp
frameset.htm
[root]\wwhelp\wwhimp\common\html
bookmark.htm
[root]\wwhelp\wwhimp\common\html
switch.js
[root]\wwhelp\wwhimp\common\scripts
Where [root] is:
On a Windows install of Server 2.0.2
C:\Program Files\VMware\VMware Server\tomcat\webapps\ui\help\en_US
On a Linux install of Server 2.0.2
/usr/lib/vmware/webAccess/tomcat/apache-tomcat-6.0.16/webapps/ui/help/en_US
-
Install the following files from the zip archive:
file
location
index.html
[root]
wwhsec.htm
[root]
api.htm
[root]\wwhelp\wwhimp
frameset.htm
[root]\wwhelp\wwhimp\common\html
bookmark.htm
[root]\wwhelp\wwhimp\common\html
switch.js
[root]\wwhelp\wwhimp\common\scripts
Note: wwhsec.htm is a newly introduced file.
No re-start of Server 2.0.2 is needed.
Acceptance of Terms Notice:
NOTICE: BY DOWNLOADING AND INSTALLING, COPYING OR OTHERWISE USING THESE KERNEL MODULES, INCLUDING DRIVERS, PLUG-INS, OR UPDATES, YOU UNDERSTAND AND AGREE THESE KERNEL MODULES ARE TO BE CONSIDERED RELATED COMPONENT(S) OF THE SOFTWARE UNDER THE TERMS OF YOUR VMWARE ESX END USER LICENSE AGREEMENT ("EULA") AND YOUR USE OF THESE KERNEL MODULES IS GOVERNED BY THE TERMS OF YOUR EULA. IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT DOWNLOAD, INSTALL, COPY OR USE THESE KERNEL MODULES. "YOU" MEANS THE NATURAL PERSON OR THE ENTITY THAT IS AGREEING TO BE BOUND THESE TERMS, THEIR EMPLOYEES AND THIRD PARTY CONTRACTORS THAT PROVIDE SERVICES TO YOU. YOU SHALL BE LIABLE FOR ANY FAILURE BY SUCH EMPLOYEES AND THIRD PARTY CONTRACTORS TO COMPLY WITH THE TERMS OF THIS AGREEMENT.
Request a Product Feature
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

