---------------------------------------------------------------------- Want a new job? http://secunia.com/secunia_security_specialist/ http://secunia.com/hardcore_disassembler_and_reverse_engineer/ International Partner Manager - Project Sales in the IT-Security Industry: http://corporate.secunia.com/about_secunia/64/ ---------------------------------------------------------------------- TITLE: VMware ESX Server update for Tomcat and Java JRE SECUNIA ADVISORY ID: SA30676 VERIFY ADVISORY: http://secunia.com/advisories/30676/ CRITICAL: Highly critical IMPACT: Security Bypass, Manipulation of data, Exposure of system information, Exposure of sensitive information, DoS, System access WHERE: >From remote OPERATING SYSTEM: VMware ESX Server 3.x http://secunia.com/product/10757/ DESCRIPTION: VMware has issued an update for VMware ESX Server. This fixes some vulnerabilities, which can be exploited by malicious people to cause a DoS (Denial of Service), bypass certain security restrictions, manipulate data, disclose sensitive/system information, or potentially compromise a vulnerable system. For more information: SA27009 SA27320 SA27398 SA28274 SA28795 SA28878 SA29239 SOLUTION: Apply patches. ESX 3.5 patch ESX350-200806404-SG: http://download3.vmware.com/software/esx/ESX350-200806404-SG.zip md5sum: 669e97880a21cce13eb7e9051f403162 http://kb.vmware.com/kb/1005219 ESX 3.0.1 and 3.0.2: The patches are not yet available. ORIGINAL ADVISORY: http://www.vmware.com/security/advisories/VMSA-2008-0010.html OTHER REFERENCES: SA27009: http://secunia.com/advisories/27009/ SA27320: http://secunia.com/advisories/27320/ SA27398: http://secunia.com/advisories/27398/ SA28274: http://secunia.com/advisories/28274/ SA28795: http://secunia.com/advisories/28795/ SA28878: http://secunia.com/advisories/28878/ SA29239: http://secunia.com/advisories/29239/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help everybody keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------