Knowledge Base
The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides

|
VMware ESX Server 3.0.3, Patch ESX303-201002204-UG: Updates Libxml2 (1018031)
Details
Release Date: March 08, 2010
|
Download Size:
1.3 MB Download Filename:
ESX303-201002204-UG.zip md5sum: 84f5a74f629241b616b2c8f2d7e2bfe6 |
|
Solution
Summaries and Symptoms
This patch contains updated Libxml2 packages that fix the following security issues in the ESX service console:
- A stack overflow flaw was found in the way libxml processes the root XML document element definition in a DTD. A remote attacker could provide an XML file, which if opened by a local user, might cause a denial-of-service application failure. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-2414 to this issue.
- Multiple use-after-free flaws were found in the way libxml parses the Notation and Enumeration attribute types. A remote attacker could provide an XML file, which if opened by a local user, might cause a denial-of-service application failure. The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-2416 to this issue.
Deployment Considerations
None beyond the required patch bundles and reboot information listed in the table, above.
Patch Download and Installation
See the vCenter Update Manager Administration Guide for instructions on using Update Manager to download and install patches to automatically update ESX 3.0.3 hosts.
To update ESX 3.0.3 hosts without using the Update Manager, download the most recent patch bundle from http://support.vmware.com/selfsupport/download/ and install the bundle by using esxupdate from the command line of the host. For more information, see the ESX Server 3 Patch Management Guide.
Request a Product Feature
To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.
Actions
KB:
- Updated:
- Categories:
- Languages:
- Product Family:
- Product(s):
- Product Version(s):

