با سلام و تبریک سال جدید و آرزوی سالی خوب برای شما مخاطبان خوب NewAdmin .
اگر پیگیرخبر های حوزه IT هستید از کشف یک باگ امنیتی بزرگ در وب سرور Apache باخبر شده اید ، این حفره امنیتی باعث شد تا خیلی از شرکت هایی که در محصولات خود از این وب سرور استفاده می کنند ، برای برطرف کردن این مشکل بزرگ اقدامی آنی و جدی انجام دهند . در این بین شرکت VMware که ید طولایی در ارائه بسته های بروز رسانی دارد ، امروز بسته نرم افزاری را برای برطرف کردن این باگ امنیتی برای برخی از محصولات خود شامل ESXI و Vcenter نسخه 5.5 ، 6 و 6.5 ارائه داده است که امکان دانلود آخرین بسته بروز رسانی امنیتی VMware از طریق این پست فراهم شده است .
نحوه نصب این بسته های بروز رسانی هر یک از این محصولات قبلا در این مطلب برای شما همراهان عزیز ارائه شده است .
VMware ESXi 6.5, Patch ESXi650-201703410-SG
VMware ESXi 6.0, Patch ESXi600-201703401-SG
VMware ESXi 5.5, Patch ESXi550-201703401-SG
Security Patch for VMware vCenter Server 6.5 b (2149073)
Full Patch for VMware vCenter Server Appliance 6.5 b (2148497)
Full Patch for VMware vCenter Server Appliance 6.0 Update 3a (2149460)
VMware ESXi 6.5, Patch ESXi650-201703410-SG
Build:5224529
Download Size:335.6 MB
md5sum:
Bulletin ID |
Category |
Severity |
Knowledge Base Article |
ESXi650-201703401-SG
|
Security
|
Critical
|
Image Profiles
Image Profile Name | Knowledge Base Article |
ESXi-6.5.0-2017034101-standard
|
|
ESXi-6.5.0-2017034101-no-tools
|
For information on patch and update classification, see KB 2014447.
Summaries and Symptoms
This patch updates the esx-base VIB to resolve the following issues:
-
- ESXi has a heap buffer overflow and uninitialized stack memory usage in SVGA. These issues may allow a guest VM to execute code on the host. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifiers CVE-2017-4902 (heap issue) and CVE-2017-4903 (stack issue) to these issues.
-
- The ESXi XHCI controller has uninitialized memory usage. This issue may allow a guest VM to execute code on the host. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4904 to this issue.
- ESXi has uninitialized memory usage. This issue may lead to an information leak. The Common Vulnerabilities and Exposures project (cve.mitre.org) has assigned the identifier CVE-2017-4905 to this issue.
VMware ESXi 6.0, Patch ESXi600-201703401-SG
Build:5224934
Download Size: 367.9 MB
sha1sum:
Host Reboot Required: Yes
Virtual Machine Migration or Shutdown Required: Yes
Bulletin ID | Category | Severity | Knowledge Base Article |
ESXi600-201703401-SG
|
Security
|
Critical
|
Image Profiles
Image Profile Name | Knowledge Base Article |
ESXi-6.0.0-20170304001-standard
|
|
ESXi-6.0.0-20170304001-no-tools
|
For information on patch and update classification, see KB 2014447.
Note: This patch is based on ESXi 6.0 Update 3. If your data center uses one of the following deployments and you do not plan to upgrade to ESXi 6.0 Update 3, see the Deployment Considerations section of this Knowledge Base article for additional information.
- ESXi 6.0 Update 1 or patches based on ESXi 6.0 Update 1
- ESXi 6.0 Update 2 or patches based on ESXi 6.0 Update 2
Summaries and Symptoms
For information about the issues fixed with the ESXi-6.0.0-20170304001-no-tools image profile, see KB 2149571.
Deployment Considerations
- If your data center uses an ESXi 6.0 Update 1 deployment or patches based on ESXi 6.0 Update 1 and you do not plan to upgrade to ESXi 6.0 Update 3, see KB 2149672.
- If your data center uses an ESXi 6.0 Update 2 deployment or patches based on ESXi 6.0 Update 2 and you do not plan to upgrade to ESXi 6.0 Update 3, see KB 2149673.
Note: To determine your ESXi deployment type, see KB 2143832.
VMware ESXi 5.5, Patch ESXi550-201703401-SG
Build:5230635
md5sum:
Bulletin ID | Category | Severity | Knowledge Base Article |
ESXi550-201703401-SG
|
Security
|
Moderate
|
Image Profiles
Image Profile Name | Knowledge Base Article |
ESXi-5.5.0-20170304001-standard
|
|
ESXi-5.5.0-20170304001-no-tools
|
For information on patch and update classification, see KB 2014447.
Summaries and Symptoms
For information about the issues fixed with the ESXi-5.5.0-20170304001-no-tools image profile, see KB 2149579.
پاسخ دهید