Secunia CSI7
Advisories
Research
Forums
Create Profile
Our Commitment
PSI
PSI API
CSI
OSI
xSI
Vulnerabilities
Programs
Open Discussions
My Threads
Create Thread
Statistics
About

Forum Thread: VMware Server Console up to date

You are currently viewing a forum thread in the Secunia Community Forum. Please note that opinions expressed here are not of Secunia but solely reflect those of the user who wrote it.

This thread was submitted in the following forum:
Programs

Relating to this vendor:
VMware
And, this specific program:
VMware Server 1.x

This thread has been marked as locked.
nfhm2k VMware Server Console up to date
Member 1st Mar, 2011 21:21
Ranking: 0
Posts: 5
User Since: 1st Mar, 2011
System Score: N/A
Location: UK
---START---

Program Name:
VMware Server 1.x

Security State:
Insecure

Download Link:
http://www.vmware.com/download/server/

Instances Found:
C:\Program Files\VMware\VMware Server Console\vmware.exe, version: 1.0.6.26355

Last System Scan (localtime):
25. Feb 2011, 00:40

Operating System:
Microsoft Windows XP Professional, Service Pack 2

---END---

1. Go here: http://register.vmware.com/content/download.html
2. Download VMware Server Windows client package: http://download3.vmware.com/software/vmserver/VMwa...
3. Run VMware-console-1.0.6-91891.exe to install latest.

There is no later version...

mogs RE: VMware Server Console up to date
Expert Contributor 1st Mar, 2011 21:48
Score: 2265
Posts: 6,266
User Since: 22nd Apr 2009
System Score: 100%
Location: UK
Hello.
It seems that even if the prog is fully patched, it remains vulnerable....see Secunia Advisory here :-
http://secunia.com/advisories/product/10733/
It also seems....from your post, that psi was still detecting the older file/ version that you may need to remove manually.
Hope this helps.....regards,

--
Was this reply relevant?
+1
-0
nfhm2k RE: VMware Server Console up to date
Member 1st Mar, 2011 22:17
Score: 0
Posts: 5
User Since: 1st Mar 2011
System Score: N/A
Location: UK
Running VMware-console-1.0.6-91891.exe only gives me the option to remove or reinstall, not upgrade.

Are you suggesting that I remove it?

I'm not sure if you're aware, but once removed it can't be used.
Was this reply relevant?
+0
-0
mogs RE: VMware Server Console up to date
Expert Contributor 1st Mar, 2011 22:30
Score: 2265
Posts: 6,266
User Since: 22nd Apr 2009
System Score: 100%
Location: UK
No, I'm not suggesting that at all.
Looking at your Troubleshoot report..... the older version/file for 1.0.6.26355 is being detected.
I'm not familiar/aware of the product, other than what I've read.
What I stated was, that having downloaded the latest version, it still seems to be showing as vulnerable in the Secunia Advisory.....link provided.


--
Was this reply relevant?
+0
-0
nfhm2k RE: VMware Server Console up to date
Member 1st Mar, 2011 22:33
Score: 0
Posts: 5
User Since: 1st Mar 2011
System Score: N/A
Location: UK
I have already tried uninstalled it and reinstalled it. The file remains with the same version, even after a re-scan.

I can only assume:

1. This is what is being shipped.
or
2. The zombie file is not being picked up by PSI for removal.

How do I proceed?
Was this reply relevant?
+0
-0
mogs RE: VMware Server Console up to date
Expert Contributor 1st Mar, 2011 22:46
Score: 2265
Posts: 6,266
User Since: 22nd Apr 2009
System Score: 100%
Location: UK
So the updated version 1.0.6.91891 is not also being detected by psi ? It may be that detection rules need updating or you may need to suggest the prog again for monitoring. Having looked thro' previous threads it does seem a while since it's had a mention.

--
Was this reply relevant?
+0
-0
nfhm2k RE: VMware Server Console up to date
Member 1st Mar, 2011 23:18
Score: 0
Posts: 5
User Since: 1st Mar 2011
System Score: N/A
Location: UK
on 1st Mar, 2011 22:46, mogs wrote:
So the updated version 1.0.6.91891 is not also being detected by psi ? It may be that detection rules need updating or you may need to suggest the prog again for monitoring. Having looked thro' previous threads it does seem a while since it's had a mention.


VMware-console-1.0.6-91891.exe installs vmware.exe version 1.0.6.26355 to C:\Program Files\VMware\VMware Server Console\
Was this reply relevant?
+0
-0
mogs RE: VMware Server Console up to date
Expert Contributor 1st Mar, 2011 23:20
Score: 2265
Posts: 6,266
User Since: 22nd Apr 2009
System Score: 100%
Location: UK
It looks as tho' you need contact the vendor of the program then.

--
Was this reply relevant?
+0
-0
nfhm2k RE: VMware Server Console up to date
Member 1st Mar, 2011 23:53
Score: 0
Posts: 5
User Since: 1st Mar 2011
System Score: N/A
Location: UK
http://twitter.com/hm2k/status/42718849640046592

Now we wait...
Was this reply relevant?
+0
-0

This thread has been marked as locked.


 Products Solutions Customers Partner Resources Company
 
 Corporate
Vulnerability Intelligence Manager (VIM)
Corporate Software Inspector (CSI)
Consumer
Personal Software Inspector (PSI)
Online Software Inspector (OSI)
 Industry
Compliance
Technology
Integration
 Customers
Testimonials
 VARS
MSSP
Technology Partners
References
 Reports
Webinars
Events
 About us
Careers
Memberships
Newsroom


 
© 2002-2014 Secunia ApS - Rued Langgaards Vej 8, 4th floor, DK-2300 Copenhagen, Denmark - +45 7020 5144
Terms & Conditions and Copyright - Privacy - Report Vulnerability