Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
ESX Server 3.0.1, Patch ESX-5031800: Security Update to Prevent Overwriting of Arbitrary Files
Details
Resolved Issues
A possible security issue with GNU tar 1.16 and 1.15.1, and possibly other versions, may allow user-assisted attackers to overwrite arbitrary files via a tar file that contains a GNUTYPE_NAMES record with a symbolic link, which is not properly handled by the extract_archive function in extract.c and extract_mangle function in mangle.c, a variant of CVE-2002-1216. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2006-6097 to this issue.
Solution
Applicability
This patch is for ESX Server 3.0.1 only. For the ESX Server 3.0.0 patch, refer to http://kb.vmware.com/kb/3003211/.
Installing the Patch
Download Instructions
Download and verify the patch bundle as follows:
-
Download patch ESX-5031800 from http://www.vmware.com/download/vi/vi3_patches.html.
-
Log into the ESX Server service console as root.
- Create a local depot directory.
# mkdir /var/updates
Note: VMware recommends you use the updates directory. - Change your working directory to /var/updates.
# cd /var/updates -
Download the tar file into the /var/updates directory.
- Verify the integrity of the downloaded tar file.
# md5sum ESX-5031800.tgzThe md5 checksum output should match the following:
c266474de27c569631b93bf566ad74f2 ESX-5031800.tgz - Extract the compressed tar archive.
# tar -xvzf ESX-5031800.tgz - Change to the newly created directory, /var/updates/ESX-5031800.
# cd ESX-5031800
Installation Instructions
# esxupdate update
If you want to run esxupdate from a different directory, you must specify the bundle path in the command:
# esxupdate -r file://<directory>/ESX-5031800 update
For example, if the host is called depot:
# esxupdate –r file:///depot/var/updates/ESX-5031800 update
During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below:
# esxupdate -v 10 -r file://<directory>/ESX-5031800 update
For more information on using esxupdate, refer to the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf.
Keywords
Feedback
- KB Article: 5031800
- Updated: Aug 14, 2009
- Products:
VMware ESX - Product Versions:
VMware ESX 3.0.x

