-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
US-CERT Current Activity
VMware Releases Security Advisory VMSA-0008-0015
Original release date: September 19, 2008 at 9:51 am
Last revised: September 19, 2008 at 9:51 am
VMware has released a Security Advisory indicating it has updated the
ESXi and ESX 3.5 packages to address a vulnerability in "openwsman".
This vulnerability is due to several buffer overflow conditions in the
handling of HTTP basic authentication headers. Exploitation of this
vulnerability may allow a remote, unauthenticated attacker to execute
arbitrary code on the host running ESXi or ESX.
US-CERT encourages users and administrators to review VMware Security
Advisory VMSA-0008-0015 and apply any necessary updates to help
mitigate the risks.
Relevant Url(s):
<http://www.vmware.com/security/advisories/VMSA-2008-0015.html>
====
This entry is available at
http://www.us-cert.gov/current/index.html#vmware_releases_security_advisory_vmsa
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
iQEVAwUBSNOv3nIHljM+H4irAQLwRggAq0b2umRTEy0lpbXft1+NEvJHTPQB9GP9
JJQSAPv2a6/cnnzHg/L7AhTxdlruUXzPARBok+vb0W3tFVHAt9NusSG1xkTjsYpM
toH7Gg6OfgL9CT6n3D8UvjYDlY4b0OosIoHc7GDvhrpF0WnG9pDp1rcLatJovFGL
THw++buICObc3UK/LxT4GJJW7sKrS9RB0iz1fc/wvCmPLBSTRI7OjONZMt5/6DHX
fJ2KWmS/SnX743PGztdsxDcaE9h8Ah8LOwTIYW5p88bDpWXuBngFA7qva7Nc9OZt
qu/hhd30VvgStLAie2QJYbgjdeQr+VJ7dOOJlKetHKUpNttAyhbI4g==
=9v20
-----END PGP SIGNATURE-----