Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

VMware ESX 3.5, Patch ESX350-201006408-SG: Updates Kerberos package (1020172)

Details

Release Date: June 24, 2010

Download Size:
527KB
Download Filename:
ESX350-201006408-SG.zip
md5sum:
a0da0fd9a8e2a9896870cd85360b6be3

 

Product Versions ESX 3.5
Build 259926
Patch Classification Security
Supersedes ESX350-200805507-SG
Requires ESX350-200911202-UG
Virtual Machine Migration or Reboot Required Yes
Host Reboot Required Yes
PRs Fixed 516886
Affected Hardware N/A
Affected Software N/A
RPMs Included krb5-libs
pam_krb5
Related CVE Numbers CVE-2009-4212

Solution

Summaries and Symptoms

This patch updates the service console package for krb5 to krb5-libs-1.2.7-71 for addressing heap-based corruptions. The update addresses multiple integer underflow flaws that were found in the way the MIT Kerberos Key Distribution Center (KDC) decrypted ciphertexts. These ciphertexts are encrypted using the Advanced Encryption Standard (AES) and ARCFOUR (RC4) encryption algorithms. A specially-crafted AES- or RC4-encrypted ciphertext from a remote KDC client might potentially lead to either a denial-of-service of the central KDC or arbitrary code execution with the privileges of the KDC (root privileges).
The Common Vulnerabilities and Exposures Project (cve.mitre.org) has assigned the name CVE-2009-4212 to this issue.

Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table, above.

Patch Download and Installation

Note: All virtual machines on the ESX host must be either shut down or migrated using vMotion before applying the patch. A reboot of the ESX host is required after applying this patch.
 
See the vCenter Update Manager Administration Guide for instructions on using Update Manager to download and install patches to automatically update ESX 3.5 hosts.

To update ESX 3.5 hosts without using Update Manager, download the most recent patch bundle from http://www.vmware.com/download/vi/vi3_patches_35.html and install the bundle using esxupdate from the command line of the host. For more information, see the ESX Server 3 Patch Management Guide.

 

Keywords

krb5, heap-based, Kerberos, ciphertexts, AES, ARCFOUR, RC4,denial-of-service, CVE-2009-4212

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 0 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
  • 0 Ratings
Actions
KB: