ESXi 5.0 < Build 721882 Multiple Vulnerabilities (remote check)

high Nessus Plugin ID 70883

Synopsis

The remote VMware ESXi 5.0 host is affected by multiple security vulnerabilities.

Description

The remote VMware ESXi 5.0 host is affected by the following security vulnerabilities :

- An error exists related to handling checkpoint files that could allow memory corruption leading to arbitrary code execution. (CVE-2012-3288)

- An error exists related to handling mobile device traffic data that could lead to denial of service conditions. (CVE-2012-3289)

Solution

Apply patch ESXi500-201206401-SG.

See Also

http://www.nessus.org/u?3004779a

http://www.vmware.com/security/advisories/VMSA-2012-0011.html

Plugin Details

Severity: High

ID: 70883

File Name: vmware_esxi_5_0_build_721882_remote.nasl

Version: 1.5

Type: remote

Family: Misc.

Published: 11/13/2013

Updated: 8/6/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.9

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Information

CPE: cpe:/o:vmware:esxi:5.0

Required KB Items: Host/VMware/version, Host/VMware/release

Exploit Ease: No known exploits are available

Patch Publication Date: 6/14/2012

Vulnerability Publication Date: 6/14/2012

Reference Information

CVE: CVE-2012-3288, CVE-2012-3289

BID: 53996

VMSA: 2012-0011