Download Patch ESX-55052 for VMware ESX Server 3.0.0
Security IssuesThis patch resolves an issue with some of the tools provided with ESX Server 3.0.0. The issue is an integer overflow in the Binary File Descriptor (BFD) library for the GNU Debugger (gdb) before version 6.3, binutils, elfutils, and possibly other packages, that allows user-assisted attackers to execute arbitrary code via a crafted object file that specifies a large number of section headers, leading to a heap-based buffer overflow. The Common Vulnerabilities and Exposures project (cve.mitre.org) assigned the name CVE-2005-1704 to this issue. ApplicabilityThis patch is for ESX Server 3.0.0 only. View KB 55052 for more information. Installing the PatchDownload InstructionsDownload and verify the patch bundle as follows :
Installation Instructions
Once you have downloaded and extracted the archive, and if you are in the directory you created above, install the update using the following command: # esxupdate update If you want to run esxupdate from a different directory, you must specify the bundle path in the command: # esxupdate -r file://<directory>/ESX-55052 update For example, if the host is called depot: # esxupdate -r file:///depot/var/updates/ESX-55052 update During the update process, logs appear on the terminal. You can specify the verbosity of esxupdate logs by using the -v option as shown below. # esxupdate -v 10 file://<directory>/ESX-55052 update For more information on using esxupdate, please refer to the Patch Management for ESX Server 3 tech note at http://www.vmware.com/pdf/esx3_esxupdate.pdf. |
||
