---------------------------------------------------------------------- Want a new job? http://secunia.com/secunia_security_specialist/ http://secunia.com/hardcore_disassembler_and_reverse_engineer/ International Partner Manager - Project Sales in the IT-Security Industry: http://corporate.secunia.com/about_secunia/64/ ---------------------------------------------------------------------- TITLE: VMware ESX Server update for Samba and vmnix SECUNIA ADVISORY ID: SA31246 VERIFY ADVISORY: http://secunia.com/advisories/31246/ CRITICAL: Highly critical IMPACT: Exposure of sensitive information, Privilege escalation, DoS, System access WHERE: >From remote OPERATING SYSTEM: VMware ESX Server 3.x http://secunia.com/product/10757/ VMware ESX Server 2.x http://secunia.com/product/2125/ DESCRIPTION: VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious, local users to disclose potentially sensitive information, to cause a DoS (Denial of Service), or to gain escalated privileges, and malicious people to compromise a vulnerable system. For more information: SA23436 SA27908 SA30108 SA30228 SOLUTION: Apply patches. -- ESX 3.5 -- ESX350-200806218-UG: http://download3.vmware.com/software/esx/ESX350-200806218-UG.zip md5sum: dfad21860ba24a6322b36041c0bc2a07 http://kb.vmware.com/kb/1005931 ESX350-200806201-UG: http://download3.vmware.com/software/esx/ESX350-200806201-UG.zip md5sum: 2888192905a6763a069914fcd258d329 http://kb.vmware.com/kb/1005894 -- ESX 2.5.4, 2.5.5, 3.0.1, and 3.0.2 -- The patches are not yet available. ORIGINAL ADVISORY: http://lists.vmware.com/pipermail/security-announce/2008/000023.html OTHER REFERENCES: SA23436: http://secunia.com/advisories/23436/ SA27908: http://secunia.com/advisories/27908/ SA30108: http://secunia.com/advisories/30108/ SA30228: http://secunia.com/advisories/30228/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------