Security scans might show that an ESX Server host contains a version of the Network Time Protocol (NTP) that is vulnerable to the bug in CVE-2009-1252.
Solution
The ESX Server 3.5 console operating system is based upon Red Hat Enterprise Linux (RHEL) 3 and is not affected by this issue.