Wednesday, July 01, 2009 1:58 PM
cmosby
New VMWare Security Advisory – SANS Internet Storm Center
digg_url = 'http://isc.sans.org/diary.html?storyid=6694&rss';
digg_title = 'New VMWare Security Advisory';
digg_skin='compact';
digg_topic = 'security';
VMWare released a new security advisory about a vulnerability in the krb5 (Kerberos) package. The vulnerability allows a remote attacker to cause a DoS or potentially execute arbitrary code on the ESX server.
According to the advisory available at http://lists.vmware.com/pipermail/security-announce/2009/000059.html all ESX versions are affected (ESXi is not affected), however, the Kerberos package is not installed by default.
In any case, I'd like to remind you to firewall and isolate your ESX servers as much as possible.