Search the VMware Knowledge Base (KB)
View by Article ID

Resolving OpenSSL Heartbleed issue CVE-2014-0160 in the Client Integration Plug-in used with vCloud Director 5.5 (2076891)

  • 0 Ratings

Symptoms

This article provides the resolution procedure for vCloud Director 5.5 in response to the OpenSSL Heartbleed vulnerability.

The Heartbleed issue affects the VMware Client Integration Plug-in which is packaged with the VMware vCloud Director 5.5. The vCloud Director server itself is not impacted.

The VMware Client Integration Plug-in is a client side component that users download and install from the vCloud Director Web console when uploading or downloading OVFs or accessing virtual machine consoles  for the first time.

The patch must be applied immediately to fix the critical security vulnerability reported in CVE-­2014-­0160. Details on this vulnerability can be found in VMware Security Advisory VMSA-2014-0004.

For details on the impact of the OpenSSL security issue, also known as Heartbleed, on VMware products and portals, see:

Purpose

vCloud Director 5.5.1.1 has been issued to address the issue in the Client Integration Plug-in. If you are currently running vCloud Director 5.5 or vCloud Director 5.5.1, upgrade to vCloud Director 5.5.1.1. If you are upgrading from vCloud Director 5.1.x, upgrade directly to vCloud Director 5.5.1.1

Resolution

The issue is resolved in vCloud Director 5.5.1.1. For more information, see the vCloud Director 5.5.1.1 Release Notes.

After you upgrade vCloud Director to version 5.5.1.1, all vCloud end users must update the VMware Client Integration Plug-in.

Update the Client Integration Plug-in

The vCloud Director Web console displays one of the following prompts to update the Client Integration Plug-in when you upload or download an OVF or access a virtual machine console.

An update to the Client Integration Plugin is available. Click the link below to download the installer.

An upgrade is available for the Client Integration Plug-in. Click OK to download the plugin.

When you see one of these prompts, take the following steps to update the Client Integration Plug-in.
  1. Download the VMware Client Integration Plug-in according to the prompt's instructions.
  2. Run the application to upgrade the Client Integration Plug-in.
    This requires restarting your Web browser.

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback

  • 0 Ratings

Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.

What can we do to improve this information? (4000 or fewer characters)




Please enter the Captcha code before clicking Submit.
  • 0 Ratings
Actions
KB: