Download Patch ESX-1121906 for VMware ESX Server 3.0.0
Security FixesThis patch provides updated texinfo packages for the service console in order to fix two security vulnerabilities. The first is an issue where a buffer overflow in the program texinfo could allow a local user to execute arbitrary code in the service console via a specially crafted texinfo file. The second issue comes from the possibility that the texinfo package could allow a local user to overwrite arbitrary files via a symlink attack on temporary files. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the names CVE-2005-3011 and CVE-2006-4810 to these issues. ApplicabilityThis patch is for ESX Server 3.0.0 only. For the related patch for ESX Server 3.0.1, please refer to http://www.vmware.com/support/vi3/doc/esx-2559638-patch.html . View KB 1121906 for more information. Installing the PatchDownload InstructionsDownload and verify the patch bundle as follows :
Installation Instructions
Once you have downloaded and extracted the archive, and if you are in the directory you created above, install the update using the following command: # esxupdate update If you want to run esxupdate from a different directory, you must specify the bundle path in the command: # esxupdate -r file://<directory>/ESX-1121906 update For example, if the host is called depot: # esxupdate -r file:///depot/var/updates/ESX-1121906 update During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below. # esxupdate -v 10 file://<directory>/ESX-1121906 update For more information on using esxupdate, please refer to the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf. |
||
