VMSA-2009-0003 : ESX 2.5.5 patch 12 updates service console package ed

This script is Copyright (C) 2009-2014 Tenable Network Security, Inc.

Synopsis :

The remote VMware ESX host is missing a security-related patch.

Description :

a. Updated ESX patch updates Service Console package ed

ed is a line-oriented text editor, used to create, display, and
modify text files (both interactively and via shell scripts).

A heap-based buffer overflow was discovered in the way ed, the GNU
line editor, processed long file names. An attacker could create a
file with a specially crafted name that could possibly execute an
arbitrary code when opened in the ed editor.

The Common Vulnerabilities and Exposures Project (cve.mitre.org)
has assigned the name CVE-2008-3916 to this issue.

See also :


Solution :

Apply the missing patch.

Risk factor :

High / CVSS Base Score : 9.3
CVSS Temporal Score : 6.9
Public Exploit Available : false

Family: VMware ESX Local Security Checks

Nessus Plugin ID: 40388 ()

Bugtraq ID: 30815

CVE ID: CVE-2008-3916