VMSA-2009-0003 : ESX 2.5.5 patch 12 updates service console package ed

This script is Copyright (C) 2009-2014 Tenable Network Security, Inc.


Synopsis :

The remote VMware ESX host is missing a security-related patch.

Description :

a. Updated ESX patch updates Service Console package ed

ed is a line-oriented text editor, used to create, display, and
modify text files (both interactively and via shell scripts).

A heap-based buffer overflow was discovered in the way ed, the GNU
line editor, processed long file names. An attacker could create a
file with a specially crafted name that could possibly execute an
arbitrary code when opened in the ed editor.

The Common Vulnerabilities and Exposures Project (cve.mitre.org)
has assigned the name CVE-2008-3916 to this issue.

See also :

http://lists.vmware.com/pipermail/security-announce/2009/000051.html

Solution :

Apply the missing patch.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: VMware ESX Local Security Checks

Nessus Plugin ID: 40388 ()

Bugtraq ID: 30815

CVE ID: CVE-2008-3916