Release Date: 2008-10-06
Critical:
Highly critical
Impact: Security Bypass
Exposure of system information
Exposure of sensitive information
DoS
System access
Where: From remote
Solution Status: Partial Fix
Software: VMware VirtualCenter 2.x
Description:
VMware has acknowledged a weakness and some vulnerabilities in VMware VirtualCenter, which can be exploited by malicious, local users to disclose sensitive information, and by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
Solution:
VirtualCenter 2.5:
Update to version 2.5 update 3 build 119838.
www.vmware.com/download/download.do
VirtualCenter 2.0.2:
Reportedly, an updated version is pending release.
Provided and/or discovered by:
1) The vendor credits Mark Woollatt.
Original Advisory:
http://www.vmware.com/security/advisories/VMSA-2008-0016.html
Other References:
SA31010:
http://secunia.com/advisories/31010/
VMware ESX Server Sun Java JDK / JRE Multiple Vulnerabilities
Release Date: 2008-10-06
Critical:
Highly critical
Impact: Security Bypass
Exposure of system information
Exposure of sensitive information
DoS
System access
Where: From remote
Solution Status: Unpatched
OS: VMware ESX Server 3.x
Description:
VMware has acknowledged some vulnerabilities in VMware ESX Server, which can be exploited by malicious people to bypass certain security restrictions, disclose system information or potentially sensitive information, cause a DoS (Denial of Service), or compromise a vulnerable system.
The vulnerabilities affect versions 3.0.1, 3.0.2, 3.0.3, and 3.5.
Solution:
Patches are reportedly pending release.
Do not follow untrusted links or browse untrusted websites.
Original Advisory:
http://www.vmware.com/security/advisories/VMSA-2008-0016.html
Other References:
SA31010:
http://secunia.com/advisories/31010/

Chowhound
Comic Vine
GameFAQs
GameSpot
Giant Bomb
TechRepublic