LANDesk Patch News Bulletin: VMware ACE Version 2.7.2 is Available 26-SEP-2010

Version 1

    LANDesk Security and Patch News

     

    Headlines

    • (September 26, 2010) VMware Inc has released an update for its VMware ACE application. Version 2.7.2 is available. The following known issues are resolved in VMware ACE 2.7.2:

         * VMware ACE Management Server for Windows updates Apache httpd to version 2.2.15

           A function in Apache HTTP Server when multithreaded MPM is used does not properly handle headers in subrequests in certain circumstances which might allow remote attackers to obtain sensitive information via a crafted request that triggers access to memory locations associated with an earlier request.

           The Apache mod_isapi module can be forced to unload a specific library before the processing of a request is complete, resulting in memory corruption. This vulnerability might allow a remote attacker to execute arbitrary code.

        * Pressing the Ctrl+Alt+Enter keys on an ACE virtual machine running in kiosk mode might cause the keyboard to become unresponsive.

        * PCI devices cannot be added back into encrypted ACE virtual machines if removed accidentally by non-ACE Administrators. To fix this issue, only ACE Administrators can add or remove PCI devices to ACE virtual machines after entering the Admin mode password.

     

           

    New Vulnerabilities

    • Vulnerability ID – VMWAREACEv2.7.2_Detect_Only

     

    Changed Vulnerabilities

    • Vulnerability ID – VMWAREACEv2.6_Manual

            (Added the replacement information.)

     

     

    New Patch Downloads

    • N/A

     

    Where to Send Feedback

    At LANDesk, we are constantly striving to improve our products and services and hope you find these changes reflective of our ongoing commitment to listen to you—our partners and customers—in providing the best possible solutions to meet your needs now and in the future.  Please continue to provide feedback by contacting our local support organization.

     

    Best regards,

    LANDesk Product Support

     

    Copyright © 2010 LANDesk Software.  All rights reserved. LANDesk is either a registered trademark or trademark of LANDesk Software, Ltd. or its affiliated entities in the United States and/or other countries. Other names or brands may be claimed as the property of others.

     

    Information in this document is provided for information purposes only.  The information presented here is subject to change without notice.  This information is not warranted to be error-free, nor subject to any other warranties or conditions, whether expressed orally or implied in law, including any implied warranties and conditions of merchantability or fitness for a particular purpose. LANDesk disclaims any liability with respect to this document and LANDesk has no responsibility or liability for any third party products of any content contained on any site referenced herein.  This document may not be reproduced or transmitted in any form or by any means, electronic or mechanical, for any purpose, without our prior written permission. For the most current product information, please visit http://www.landesk.com.