We have a ESX Server 3.5.0 build-110268 (all patches installed). However, our security operation staffs found the following vulnerabilities in OpenSSH v3.6, embedded in ESX 3:
OpenSSH Multiple Memory Management Vulnerabilities
OpenSSH Signal Handling Vulnerability (RHSA-2006-0697)
OpenSSH GSSAPI Credential Disclosure Vulnerability
OpenSSH Local SCP Shell Command Execution Vulnerability (FEDORA-2006-056)
OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
I checked the patches currently available (76) and none were required.
This is the info about OpenSSH
openssh-3.6.1p2-33.30.14vmw
openssh-server-3.6.1p2-33.30.14vmw
openssh-clients-3.6.1p2-33.30.14vmw
How can I fix these issues?
OpenSSH Multiple Memory Management Vulnerabilities
OpenSSH Signal Handling Vulnerability (RHSA-2006-0697)
OpenSSH GSSAPI Credential Disclosure Vulnerability
OpenSSH Local SCP Shell Command Execution Vulnerability (FEDORA-2006-056)
OpenSSH Reverse DNS Lookup Access Control Bypass Vulnerability
I checked the patches currently available (76) and none were required.
This is the info about OpenSSH
openssh-3.6.1p2-33.30.14vmw
openssh-server-3.6.1p2-33.30.14vmw
openssh-clients-3.6.1p2-33.30.14vmw
How can I fix these issues?
Attachments:
- esxupdate.txt (7.5 K)