Original URL: http://www.channelregister.co.uk/2007/09/24/vmware_update/
Wall Street darling VMware released patches that address multiple vulnerabilities in its products this week.
The virtualisation firm, which recently went public, issued updates to fix bugs in various versions of VMware ACE, VMware Player, VMware Server and VMware Workstation.
The flaws range in severity, with some allowing malicious users to crash vulnerable systems or local users to gain escalated privileges, while others enable hackers to inject malicious code into vulnerable systems.
Security notification firm Secunia has a summary of the update here (http://secunia.com/advisories/26890). Credit for discovering the bugs goes to security researchers at ISS, McAfee, and Foundstone.
A more detailed summary of the bugs can be found on a posting by VMWare on a full disclosure mailing list here (http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/065902.html).
Many of the updates address vulnerabilities in underlying third-party code that have been known about for some time, the SANS Institute's Internet Storm Centre (ISC) notes. The increased use of virtualisation in corporate data centres and elsewhere has raised the profile of the technology.
Handlers at the ISC describe how the technology is showing signs of becoming a battleground between security researchers and crackers, as well as outlining a possible response, in a thought-provoking posting here (http://isc.sans.org/diary.html?storyid=3411). ®
How safe is VMware's hypervisor? (27 March 2008)
http://www.channelregister.co.uk/2008/03/27/vmware_hypervisor_claims/
VMware opens its products to security apps (28 February 2008)
http://www.channelregister.co.uk/2008/02/28/vmware_api_announcement/
VMWare update lances virtual bugs (22 February 2008)
http://www.channelregister.co.uk/2008/02/22/vmware_update/
EMC shares ride VMware madness (25 October 2007)
http://www.channelregister.co.uk/2007/10/25/emc_announces_q3_2007_earnings/
VMware makes storage fluid (8 October 2007)
http://www.channelregister.co.uk/2007/10/08/vmware_3_5/
VMware opens certification program to storage vendors (28 September 2007)
http://www.channelregister.co.uk/2007/09/28/vmware_adds_storage_certification/
Sun to virtualize boxes, storage and NICs with 'Project Virginia' (18 September 2007)
http://www.channelregister.co.uk/2007/09/18/virtualization_project_virginia_sun/
Acronis grabs virtual servers by their backups (17 September 2007)
http://www.channelregister.co.uk/2007/09/17/acronis_echo_true_image/
Virtualization standards becoming a reality (13 September 2007)
http://www.channelregister.co.uk/2007/09/13/dmtf_drafts_virtualization_standards/
Canonical and VMware team on mini-Ubuntu (13 September 2007)
http://www.channelregister.co.uk/2007/09/13/ubuntu_jeos_vmware/
VMware's 'Calista Flockhart' hypervisor may or may not change the world (11 September 2007)
http://www.channelregister.co.uk/2007/09/11/vmworld_esxserver3i/
Virtualisation gets trendy (6 June 2007)
http://www.channelregister.co.uk/2007/06/06/virtualisation_gets_trendy/
© Copyright 2008