VMware ESXi 6.0, Patch ESXi-6.0.0-20150901001s-standard
search cancel

VMware ESXi 6.0, Patch ESXi-6.0.0-20150901001s-standard

book

Article ID: 334721

calendar_today

Updated On:

Products

VMware vSphere ESXi

Issue/Introduction

Profile Name
ESXi-6.0.0-20150901001s-standard
Build
For build information, see KB 2124715.
Vendor
VMware, Inc.
Release Date
Sep 10, 2015
Acceptance Level
PartnerSupported
Affected Hardware
N/A
Affected Software
N/A
Affected VIBs
  • VMware:esx-base:6.0.0-0.14.3017641
  • VMware:tools-light:6.0.0-0.14.3017641
PRs Fixed
1397920, 1417404, 1424673, 1433810, 1448301, 1464555, 1417411, 1445643, 1474674
Related CVE numbers


Environment

VMware vSphere ESXi 6.0

Resolution

Summaries and Symptoms

This patch resolves the following issues:

  • ESXi has been modified to only support AES256-CTS/AES128-CTS/RC4-HMAC encryption for Kerberos communication between ESXi and Active Directory.


  • The ESXi userworld OpenSSL library is updated to version openssl-1.0.1m.


  • The ESXi userworld libxml2 library is updated to resolve multiple security issues. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2014-0191 and CVE-2014-3660 to these issues.

  • The libPNG library has been updated to libpng-1.6.16.


  • The Python third-party library is updated to version 2.7.9.


  • Support for SSLv3: Support for SSLv3 has been disabled by default. For further details, see Knowledge Base article 2121021.


  • The VMTools libPNG and libxml2 libraries are updated to versions 1.2.52 and 2.9.2 respectively.

  • The VMTools OpenSSL library is updated to version openssl-0.9.8zg.

  • The FUSE library has been updated to libfuse 2.9.4.

Deployment Considerations

None beyond the required patch bundles and reboot information listed in the table above.

Patch Download and Installation

An ESXi system can be updated using the image profile, by using the esxcli software profile command. For details, see the vSphere Command-Line Interface Concepts and Examples and the VMware vSphere Upgrade Guide. ESXi hosts can also be updated by manually downloading the patch ZIP file from the Patch Manager Download Portal and installing the VIB by using the esxcli software vib command.