Solomonster

Back in 10.

Thursday, February 28, 2008

 

RANT: VMWare Vulnerability

If you don't use a piece of software called VMWare, then you're not going to want to read the rest of this. If you DO use VMWare, then perhaps you've heard about the newly announced vulnerability that's got the technology media all in a tizzy (maybe it just seems that way because I'm concerned about it!) exposing access via VMWare's shared folders.

Wait! Don't go away! This is where it gets ANNOYING! I've read at least half a dozen articles on this hole and only just today did I decide to go and take a look at the vendor's web site for news on how I can protect my servers from this thing. I'd like to paste in a portion of their warning, the part telling us which products are affected:

Vulnerable packages


All versions of VMware's desktop products that include the Shared Folders feature up to:



  • VMWare Workstation 6.0.2
  • VMWare Workstation 5.5.4
  • VMWare Player 2.0.2
  • VMWare Player 1.0.4
  • VMWare ACE 2.0.2
  • VMWare ACE 1.0.2


Non-vulnerable packages



  • VMWare ESX
  • VMWare Server

Now, the media articles I've been reading are all, "VMWare-this..." and "VMWare-that...", when the more accurate finger would be pointing at "VMWare Workstation-this..." and "VMWare Player that..."

Enterprises use ESX server. Smaller companies and individuals, for the most part, use the free VMWare Server.

Tech Media: Why are you frightening us with lumping in Server and ESX with the vulnerable products???


Comments: Post a Comment





<< Home

Archives

May 2004   June 2004   August 2004   September 2004   October 2004   November 2004   January 2005   March 2005   April 2005   May 2005   June 2005   July 2005   September 2005   October 2005   November 2005   December 2005   January 2006   February 2006   March 2006   April 2006   May 2006   June 2006   July 2006   August 2006   September 2006   October 2006   November 2006   December 2006   January 2007   March 2007   June 2007   July 2007   August 2007   September 2007   October 2007   February 2008   March 2008   April 2008   May 2008   June 2008   July 2008   August 2008   September 2008   October 2008   December 2008   January 2009  

This page is powered by Blogger. Isn't yours?

Subscribe to Posts [Atom]