Release date:
Updated on: 2013-02-27
Affected Systems:
VMWare vCenter 5.0
VMWare vCenter 4.1 Update 2
Description:
--------------------------------------------------------------------------------
Bugtraq id: 58139
Cve id: CVE-2012-6326
VMware vCenter Server allows you to quickly deploy virtual machines and monitor the performance of physical servers and virtual machines. You can deploy, monitor, and manage virtualized IT environments on a single interface and ensure the best service level.
VCenter Server and vCenter Server Appliance (vCSA) allow unauthenticated remote users to create ultra-large log entries. There is a security vulnerability in implementation that allows attackers to populate the system volumes of vCenter hosts or device VMS, and cause a denial of service.
<* Source: vendor
Link: http://www.vmware.com/security/advisories/VMSA-2012-0018.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
VMWare
------
VMWare has released a Security Bulletin (VMSA-2012-0018) and patches for this:
VMSA-2012-0018: VMware security updates for vCSA, vCenter Server, and ESXi
Link: http://www.vmware.com/security/advisories/VMSA-2012-0018.html
Patch download:
VCenter Server 5.1.0b
---------------------------
Download link:
Https://downloads.vmware.com/d/info/datacenter_cloud_infrastructure/vmware_vsphere/5_1
Release Notes:
Https://www.vmware.com/support/vsphere5/doc/vsphere-vcenter-server-510b-release-notes.html
VCenter Server 5.0 Update 2
---------------------
Download link:
Https://downloads.vmware.com/d/info/datacenter_cloud_infrastructure/vmware_vsphere/5_0
Release Notes:
Https://www.vmware.com/support/vsphere5/doc/vsp_vc50_u2_rel_notes.html
VCenter Server 4.1 Update 3
---------------------------
Download link:
Https://downloads.vmware.com/d/info/datacenter_cloud_infrastructure/vmware_vsphere/4_1
Release Notes:
Https://www.vmware.com/support/vsphere4/doc/vsp_vc41_u3_rel_notes.html
ESXi and ESX
------------
The download for ESXi nodes des vCenter Server Appliance.
Https://my.vmware.com/web/vmware/downloads
ESX 5.1
--------
File: ESXi510-201212001.zip
Md5sum: 81d562c00942973f13520afac4868748
Sha1sum: ec1ff6d3e3c9b%252ba1b710c74119f%4786
Http://kb.vmware.com/kb/2035775
ESXi510-201212001 contains ESXi510-201212101
ESX 5.0
--------
File: update-from-esxi5.0-5.0_update02.zip
Md5sum: ab8f7f258932a39f7d3e7877787fd198
Sha1sum: b65bacab4e38cf144e223cff4770501b5bd23334
Http://kb.vmware.com/kb/2033751
Update-from-esxi5.0-5.0_update02.zip contains ESXi500-201212101