Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

Remediation of CVE-2009-3731 on VMware Server 2.0.2 (1016594)

Details

This KB provides remediation for a security vulnerability that is present in VMware Server 2.0.2. This issue is documented in http://www.vmware.com/security/advisories/VMSA-2009-0017.html and is identified by CVE-2009-3731.

 

Vmware Server 1.0.x is not affected by this issue.

Solution

These steps remediate CVE-2009-3731 on Server 2.0.2 running on Windows and running on Linux:

  1. Download the zip archive linked from this KB article.
    Filename: VMwareServer202-CVE-2009-3731.zip
    Download location: http://download3.vmware.com/software/vi/VMwareServer202-CVE-2009-3731.zip
    MD5: c1f2fb4535acb0728d6de6b971e449de
    SHA1: 018d41d4fbc0586d8f6a4e00eba05a454b4d8f26

    Note: Read the Acceptance of Terms Notice, below, before downloading.

  2. Verify that the MD5 or SHA1 sum of the downloaded file matches the value listed in the step above.

  3. Unzip the archive.

  4. Backup the following files

    file

    location

    index.html

    [root]

    api.htm

    [root]\wwhelp\wwhimp

    frameset.htm

    [root]\wwhelp\wwhimp\common\html

    bookmark.htm

    [root]\wwhelp\wwhimp\common\html

    switch.js

    [root]\wwhelp\wwhimp\common\scripts


    Where [root] is:
    On a Windows install of Server 2.0.2
    C:\Program Files\VMware\VMware Server\tomcat\webapps\ui\help\en_US
    On a Linux install of Server 2.0.2
    /usr/lib/vmware/webAccess/tomcat/apache-tomcat-6.0.16/webapps/ui/help/en_US

  5. Install the following files from the zip archive:

    file

    location

    index.html

    [root]

    wwhsec.htm

    [root]

    api.htm

    [root]\wwhelp\wwhimp

    frameset.htm

    [root]\wwhelp\wwhimp\common\html

    bookmark.htm

    [root]\wwhelp\wwhimp\common\html

    switch.js

    [root]\wwhelp\wwhimp\common\scripts


    Note: wwhsec.htm is a newly introduced file.
    No re-start of Server 2.0.2 is needed.

    Acceptance of Terms Notice:
    NOTICE: BY DOWNLOADING AND INSTALLING, COPYING OR OTHERWISE USING THESE KERNEL MODULES, INCLUDING DRIVERS, PLUG-INS, OR UPDATES, YOU UNDERSTAND AND AGREE THESE KERNEL MODULES ARE TO BE CONSIDERED RELATED COMPONENT(S) OF THE SOFTWARE UNDER THE TERMS OF YOUR VMWARE ESX END USER LICENSE AGREEMENT ("EULA") AND YOUR USE OF THESE KERNEL MODULES IS GOVERNED BY THE TERMS OF YOUR EULA. IF YOU DO NOT AGREE TO THESE TERMS, YOU MAY NOT DOWNLOAD, INSTALL, COPY OR USE THESE KERNEL MODULES. "YOU" MEANS THE NATURAL PERSON OR THE ENTITY THAT IS AGREEING TO BE BOUND THESE TERMS, THEIR EMPLOYEES AND THIRD PARTY CONTRACTORS THAT PROVIDE SERVICES TO YOU. YOU SHALL BE LIABLE FOR ANY FAILURE BY SUCH EMPLOYEES AND THIRD PARTY CONTRACTORS TO COMPLY WITH THE TERMS OF THIS AGREEMENT.

 

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 3 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 3 Ratings
Actions
KB: