-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Reference: CERT-EU Security Advisory 2013-0034 Title: VMware ESX Execute arbitrary code/commands [1] Version history: 04.05.2013 Initial publication Summary ======= VMware ESXi security updates for third party library. CVE number: CVE-2012-5134 CVSS v2 Base Score:6.8 (MEDIUM) (AV:N/AC:M/Au:N/C:P/I:P/A:P) [2] Vulnerable systems ================== VMware ESX VMware ESXi Original Details [1] ================ The ESXi userworld libxml2 library has been updated to resolve a security issue. What can you do? ================ Download the patch for your version. [3] If there is no patch for your version of the product, it may be necessary to upgrade to a higher version. What to tell your users? ======================== N/A More information ================ [1] http://www.vmware.com/security/advisories/VMSA-2013-0004.html [2] http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2012-5134 [3] https://my.vmware.com/web/vmware/downloads Best regards, CERT-EU Pre-configuration Team (http://cert.europa.eu) Phone: +32.2.2990005 / e-mail: cert-eu@ec.europa.eu PGP KeyID 0x46AC4383 FP: 9011 6BE9 D642 DD93 8348 DAFA 27A4 06CA 46AC 4383 Privacy Statement: http://cert.europa.eu/cert/plainedition/en/cert_privacy.html -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.4.10 (GNU/Linux) iQIcBAEBAgAGBQJRXuj3AAoJEPpzpNLI8SVopeoP/3c7GJ3kI4YNUbLBmRzk/eUL tLbUUFVbnGlt+SMlkevMz3ptW8LGIVG8dMmR/ixGF1FTrRpr4WRpXOQ0UoXtvYqw 28OhEFrSw86Rrj7BNB7SQukaZzW5m3X5Z82hzaMM4ULaq8/w5DAHCbnsmNjhkR9Q TyBY31jKXyOxww0LRkq+Fp79FxjywmstC7+eXsQ9wlcU/Pbo3Mk1yff1nUfVE01w 7i0YYTLlyx2D2MyxWTWimZeXfS+84AkuGw63mfc/H5HIcW0EefbC6yU1Avh91X9h hQWV/nDlIB6GxlK73jWvbatpwdDo1m/zJefP2iUD0N4XbDGii6dEcOLZyEOmk1hF Ep41axgsGZkM4g8POPDhOMPRPdnIuCYSdAUHGy/u0FC+ZNjOYZBazYEFLkqYS9B3 b1XoKmNbAYyLDgqoNtoR7hhXuSKx+XBwjiWzf5IfXu9IFV9BAZ7zGBJ+7goDwroO iVrOb5wKWG94JDhVPTKECljSnpq+srJuW/kQXP1QbK8KnkJSZ20N8/GT69GxG1yh z/fNE02JBFJbR2+1wa5umG5CXwO5VOXzX8j0s52yQNAqsYOonroYBgqOSMLiSzOw XSW3a9jD5NcI4P6K3i5q5ygW+j2T0QMgA7owYFLZO3my9eT4/SfzJY7lAU9KFk2x aCsodCnwp8uDKH78JzWi =MdAF -----END PGP SIGNATURE-----