Top Stories
|
VMware updates take aim at bug swarm24 Sep 2007 14:57 Flaw fillerWall Street darling VMware released patches that address multiple vulnerabilities in its products this week. The virtualisation firm, which recently went public, issued updates to fix bugs in various versions of VMware ACE, VMware Player, VMware Server and VMware Workstation. The flaws range in severity, with some allowing malicious users to crash vulnerable systems or local users to gain escalated privileges, while others enable hackers to inject malicious code into vulnerable systems. Security notification firm Secunia has a summary of the update here. Credit for discovering the bugs goes to security researchers at ISS, McAfee, and Foundstone. A more detailed summary of the bugs can be found on a posting by VMWare on a full disclosure mailing list here. Many of the updates address vulnerabilities in underlying third-party code that have been known about for some time, the SANS Institute's Internet Storm Centre (ISC) notes. The increased use of virtualisation in corporate data centres and elsewhere has raised the profile of the technology. Handlers at the ISC describe how the technology is showing signs of becoming a battleground between security researchers and crackers, as well as outlining a possible response, in a thought-provoking posting here. ® 1 comment posted — Comment period finished infest host OSPosted: 23:36 24th September 2007
Track this type of story as a custom Atom/RSS feed or by email. Related storiesVMware opens its products to security apps (28 February 2008)
|
Breaking Hardware News
Qimonda began sampling 512Mb GDDR 5 memory silicon in November 2007 and now, six months on, it's ready to ship the chip in volume - if anyone wants it, that is.
Newsletter |