Knowledge Base

Search the Knowledge Base: |
Search the Knowledge Base: |
Security Response to CAN-2004-0415: 2.4 Linux Kernel Kernel Memory Vulnerability
Details
A security software audit warns that an ESX Server machine may have the security vulnerability described at:
cve.mitre.org/cgi-bin/cvename.cgi?name=CAN-2004-0415.
How can I protect the server? Does VMware have a fix for this?
Solution
This vulnerability affects Linux 2.4 kernels in general. It applies to ESX Server because the VMware Service Console is based on the Linux 2.4 kernel.
The Linux kernel fails to validate 64-bit file pointers properly, allowing an attacker to access kernel memory. This could allow an attacker to read sensitive data, such as cached passwords.
VMware has addressed this vulnerability as of ESX Server 2.5. VMware also provides updates for ESX 2.1.x, 2.0.x and 1.5.2 in the following security updates:
Keywords
Feedback
- KB Article: 1431
- Updated: Aug 14, 2009
- Products:
VMware ESX - Product Versions:
VMware ESX 2.0.x
VMware ESX 2.1.x
VMware ESX 2.5.x

