The Channel logo


By | John Leyden 22nd February 2008 12:01

VMWare update lances virtual bugs

Samba and Python bugs wiggle into virtualisation software

VMware has updated ESX Server to defend against multiple holes in its virtualisation software.

A flaw involving the aacraid SCSI driver might be abused by malicious local users to bypass security restrictions or crash vulnerable systems. The security bug affects both VMware ESX Server 2.x and 3.x versions of the software.

Vulnerable systems could also be compromised by remote hackers with a separate flaw in the service console packages supported by ESX Server.

A stack buffer overflow flaw in the way Samba authenticates remote users and an integer overflow involving the way Python's Perl-Compatible Regular Expression (PCRE) module handles certain regular expressions both allow hackers to inject code into vulnerable systems, as explained in an advisory by VMWare published on Thursday here.

Discovery of the flaws is credited to Adaptec, security notification firm Secunia, and Google. Secunia has published an overview of the bugs here.

The increased use of virtualisation in corporate data centres and elsewhere has raised the profile of the technology. Security handlers at the SANS Institute's Internet Storm Centre described how the technology is showing signs of becoming a battleground between security researchers and crackers, as well as outlining a possible response, in an article published last September here. ®

comment icon Read 2 comments on this article alert Send corrections


Frank Jennings

What do you do? Use manual typwriters or live in a Scottish croft? Our man advises
A rusty petrol pump at an abandoned gas station. Pic by Silvia B. Jakiello via shutterstock

Trevor Pott

Among other things, Active Directory needs an overhaul
Baby looks taken aback/shocked/affronted. Photo by Shutterstock

Kat Hall

Plans for 2 million FTTP connections in next four years 'not enough'
Microsoft CEO Satya Nadella


League of gentlemen poster - Tubbs and Edward at the local shop. Copyright BBC
One reselling man tells his tale of woe