|
|
|
|
| |
Credit:
The original article can be found at: http://lists.vmware.com/pipermail/security-announce/2010/000080.html
|
| |
Vulnerable Systems:
* VMware ESX version 3.5
* VMware ESX version 3.0.3
Immune Systems:
* VMware VirtualCenter on Windows
* VMware hosted *
* VMware ESXi
* VMware ESX version 4.0
* VMware ESX version 2.5.5
* hosted products are VMware Workstation, Player, ACE, Server, Fusion.
A divide-by-zero flaw was identified in the snmpd daemon belonging to VMWare ESX. A remote attacker could issue a specially crafted GETBULK request that could cause the snmpd daemon to fail. This vulnerability was introduced by an incorrect fix for CVE-2008-4309.
Patch Availability:
Please review the patch/release notes for your product and version and verify the md5sum of your downloaded file.
ESX 3.5
-------
ESX350-201002401-SG
http://download3.vmware.com/software/vi/ESX350-201002401-SG.zip
md5sum: a91428cb6bc2da794f581aefd5eef010
http://kb.vmware.com/kb/1017660
CVE Information:
CVE-2009-1887
Disclosure Timeline:
2010-02-16 Advisory Published
|
|
|
|
|