Fri, May 29 2009 13:13
Don
VMware Releases Security Advisory - May 29, 2009
VMware has released a security advisory
to address multiple vulnerabilities in VMware Workstation, Player, ACE,
Server, Fusion, ESX, and ESXi. The first of these vulnerabilities is
due to a error in the VMware Descheduled Time Accounting driver.
Exploitation of this vulnerability may result in denial of service in
Windows-based virtual machines. The second vulnerability is due to a
known error in the libpng package used by some VMware products.
Exploitation of this vulnerability may allow an attacker to execute
arbitrary code.
US-CERT encourages users and administrators to review the VMware security advisory and apply any necessary updates to help mitigate the risks
http://www.us-cert.gov/current/index.html#vmware_releases_security_advisory2
Filed under: Advisories / Bulletins