Release date:
Updated on:
Affected Systems:
VMWare ESX 4.1
VMWare ESXi 1, 4.1
Description:
--------------------------------------------------------------------------------
Bugtraq id: 47625
Cve id: CVE-2011-1786
VMware ESXi is an embedded hypervisor that does not require other basic operating systems to run directly on server hardware.
VMware ESXi and ESX "lsassd" services have a remote denial of service vulnerability. Remote attackers can exploit this vulnerability to interrupt the "lsassd" service, resulting in service unavailability.
By sending malicious network traffic to the ESXi or ESX host, attackers can use up available sockets to block connection to the host. When the host cannot be connected, its virtual machine will continue to run and has a network connection, but it may need to restart the ESXi or ESX host to reconnect to the host.
<* Source: VMware (vmware-security-alert@vmware.com)
Link: http://www.securityfocus.com/archive/1/517739
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://www.vmware.com