Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
ESX Server 3.0.0, Patch ESX-3616065: Third Party Code Library Security Update
Details
Security Issues
This patch updates the third-party code library zLib in order to address potential security issues with older versions of this library.
The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2005-2096, CVE-2005-1849, and CAN-2003-0107 to this issue.
Solution
Applicability
This patch is for ESX Server 3.0.0 only. For the related patch for ESX Server 3.0.1, refer to http://kb.vmware.com/kb/9916286.
Installing the Patch
Download Instructions
Download and verify the patch bundle as follows :
- Download patch ESX-3616065 from http://www.vmware.com/download/vi/vi3_patches.html.
- Log into the ESX Server service console as root.
- Create a local depot directory.
# mkdir /var/updates
Note: VMware recommends that you use the updates directory.
- Change your working directory to /var/updates.
# cd /var/updates
- Download the tar file into the /var/updates directory.
- Verify the integrity of the downloaded tar file.
# md5sum ESX-3616065.tgz
The md5 checksum output should match the following:
90e4face2edaab07080531a37a49ec01 ESX-3616065.tgz
- Extract the compressed tar archive.
# tar -xvzf ESX-3616065.tgz
- Change to the newly created directory, /var/updates/ESX-3616065.
# cd ESX-3616065
Installation Instructions
| Note: All virtual machines on the host must be either shut down or migrated using VMotion before applying the patch. A reboot of the ESX Server host is required after applying this patch. |
After you have downloaded and extracted the archive, and if you are in the directory you created above, install the update using the following command:
# esxupdate update
If you want to run esxupdate from a different directory, you must specify the bundle path in the command:
# esxupdate -r file://<directory>/ESX-3616065 update
For example, if the host is called depot:
# esxupdate –r file:///depot/var/updates/ESX-3616065 update
During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below:
# esxupdate -v 10 -r file://<directory>/ESX-3616065 update
For more information on using esxupdate, please refer to the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf.
Keywords
Feedback
- KB Article: 3616065
- Updated: Aug 14, 2009
- Products:
VMware ESX - Product Versions:
VMware ESX 3.0.x

