2009 T-0024 multiple vulnerabilities in the Linux kernel

I'm trying to create a host of U4 ESX 3.5 compatible DISA STIG and coming across this when you run the SRR script against my test host. After trying to search online and through vmware communities I don't see anything here where this has been patched/mitigated by vmware.

This finding is listed as a category 1 and possibly us keep to get an ot ATO IATO.

ESX version 3.5 update 4

Hello

Remember that ESX is NOT LINUX, which is the kernel used for the console service not the kernel used for ESX (which is the vmkernel and hypervisor). You may need to develop a control offset as there is NO update for the ESX service console from the version of the core beyond that and you really can't update the kernel using a standard RHEL kernel is. This is a system of RHEL3 U8.

This must be a new addition because the last time I ran the UNIX SRR one-on-one system 3.5 this response wasn't there.

Best regards

Edward L. Haletky VMware communities user moderator, VMware vExpert 2009, url = http://www.virtualizationpractice.comvirtualization practical analyst [url]
"Now available: url = http://www.astroarch.com/wiki/index.php/VMware_Virtual_Infrastructure_Security' VMware vSphere (TM) and Virtual Infrastructure Security: securing the virtual environment ' [url]
Also available url = http://www.astroarch.com/wiki/index.php/VMWare_ESX_Server_in_the_Enterprise"VMWare ESX Server in the enterprise" [url]
[url =http://www.astroarch.com/wiki/index.php/Blog_Roll] SearchVMware Pro [url] | URL = http://www.astroarch.com/blog Blue Gears [url] | URL = http://www.astroarch.com/wiki/index.php/Top_Virtualization_Security_Links Top security virtualization [url] links | URL = http://www.astroarch.com/wiki/index.php/Virtualization_Security_Round_Table_Podcast Virtualization Security Table round Podcast [url]

Tags: VMware

Similar Questions

  • ODI 12 c not dΘmarre after the Linux kernel update

    Hi all

    Currently, I am having trouble starting my 12 c ODI after that I updated a bunch of kernel and rebooted the machine.

    The work formerly configuration was as follows:

    Linux oraclelinux6.localdomain 3.8.13 - 35.3.4.el6uek.x86_64 #2 SMP Wed Jul 30 00:59:13 PDT 2014 x86_64 x86_64 x86_64 GNU/Linux

    ODI Standalone Edition Version 12.1.3

    Build ODI_12.1.3.0.0_GENERIC_140617.0542

    Java (TM) Platform 1.7.0_67

    Then I updated the package kernel - uek.x86_64, the output of the command "yum update" was the following:

    sudo yum update kernel - uek.x86_64 - y
    Loaded modules: refresh-packagekit, security
    Implementation of the update process
    Resolution of dependencies
    --> Running transaction control
    -> Package kernel - uek.x86_64 0:3.8.13 - 44.1.1.el6uek will be installed
    --> Processing dependency: kernel-firmware = 3.8.13 - 44.1.1.el6uek for package: kernel-uek - 3.8.13 - 44.1.1.el6uek.x86_64
    --> Running transaction control
    -> Package kernel-uek - firmware.noarch 0:3.8.13 - 44.1.1.el6uek will be installed
    --> Resolution of dependencies finished
    --> Running transaction control
    -> Package kernel - uek.x86_64 0:2.6.39 - 400.17.1.el6uek will be deleted
    -> Package kernel-uek - firmware.noarch 0:2.6.39 - 400.17.1.el6uek will be deleted
    --> Resolution of dependencies finished


    Resolved dependencies

    ===========================================================================================================================
    Package Arch Version repository size
    ===========================================================================================================================
    Installation:
    kernel-uek x86_64 3.8.13 - 44.1.1.el6uek public_ol6_UEKR3_latest 41 M
    Disassembly:
    2.6.39 - 400.17.1.el6uek @ol6_UEK_base 101 M x86_64 kernel-uek
    kernel-uek-firmware noarch 2.6.39 - 400.17.1.el6uek @ol6_UEK_base 5.0 M
    Install the dependencies:
    kernel-uek-firmware noarch 3.8.13 - 44.1.1.el6uek public_ol6_UEKR3_latest 1.9 M

    Summary of the operation
    ===========================================================================================================================
    Install 2 package (s)
    Remove the 2 package (s)

    Download size: 43 M
    Download packages:
    (1/2): kernel-uek - 3.8.13 - 44.1.1.el6uek.x86_64.rpm |  41 MO 00:55
    (2/2): kernel-uek-firmware - 3.8.13 - 44.1.1.el6uek.noarch.rpm | 1.9 MB, 00:02
    ---------------------------------------------------------------------------------------------------------------------------
    Total                                                                                          761 kB/s |  43 MO 00:58
    Running rpm_check_debug
    Running Transaction test
    Successful Test transaction
    Transaction running
    Installation: kernel-uek-firmware - 3.8.13 - 44.1.1.el6uek.noarch 1/4
    Installation: kernel-uek - 3.8.13 - 44.1.1.el6uek.x86_64 2/4
    Cleaning: kernel-uek - 2.6.39 - 400.17.1.el6uek.x86_64 3/4
    Cleaning: kernel-uek-firmware - 2.6.39 - 400.17.1.el6uek.noarch 4/4
    Audit: kernel-uek-firmware - 3.8.13 - 44.1.1.el6uek.noarch 1/4
    Audit: kernel-uek - 3.8.13 - 44.1.1.el6uek.x86_64 2/4
    Audit: kernel-uek - 2.6.39 - 400.17.1.el6uek.x86_64 3/4
    Audit: kernel-uek-firmware - 2.6.39 - 400.17.1.el6uek.noarch 4/4


    Deleted:
    core - uek.x86_64 0:2.6.39 - 400.17.1.el6uek
    kernel-uek - firmware.noarch 0:2.6.39 - 400.17.1.el6uek

    Installed:
    core - uek.x86_64 0:3.8.13 - 44.1.1.el6uek

    Dependency installed:
    kernel-uek - firmware.noarch 0:3.8.13 - 44.1.1.el6uek

    Complete!

    The broken configuration after the update of the kernel is as follows:

    Linux oraclelinux6.localdomain 3.8.13 - 44.1.1.el6uek.x86_64 #2 SMP Wed Sep 10 06:10:25 CDT 2014 x86_64 x86_64 x86_64 GNU/Linux

    ODI Standalone Edition Version 12.1.3

    Build ODI_12.1.3.0.0_GENERIC_140617.0542

    Java (TM) Platform 1.7.0_67

    When you try to start ODI-Studio after the reboot of the machine, the following Java exception appears:

    Merge Oracle Data Integrator Studio 12 c
    Copyright (c) 1997, 2014, Oracle and/or its affiliates. All rights reserved.

    2014-10-08 15:24:15.025 NOTIFICATION installation area set to file:/oradisk/Oracle/Middleware/Oracle_Home/
    java.lang.RuntimeException: Exception in org.eclipse.osgi.framework.internal.core.SystemBundleActivator.start () of org.eclipse.osgi bundle.
    at org.eclipse.osgi.framework.internal.core.InternalSystemBundle.resume(InternalSystemBundle.java:233)
    at org.eclipse.osgi.framework.internal.core.Framework.launch(Framework.java:657)
    at org.eclipse.osgi.framework.internal.core.EquinoxLauncher.internalInit(EquinoxLauncher.java:69)
    at org.eclipse.osgi.framework.internal.core.EquinoxLauncher.init(EquinoxLauncher.java:37)
    at org.eclipse.osgi.launch.Equinox.init(Equinox.java:178)
    at org.netbeans.modules.netbinox.Netbinox.init(Netbinox.java:84)
    at org.netbeans.core.netigso.Netigso.prepare(Netigso.java:166)
    at org.netbeans.NetigsoHandle.turnOn(NetigsoHandle.java:127)
    at org.netbeans.ModuleManager.enable(ModuleManager.java:1176)
    at org.netbeans.ModuleManager.enable(ModuleManager.java:1011)
    at org.netbeans.core.startup.ModuleList.installNew (ModuleList.java:340)
    at org.netbeans.core.startup.ModuleList.trigger (ModuleList.java:276)
    at org.netbeans.core.startup.ModuleSystem.restore (ModuleSystem.java:301)
    at org.netbeans.core.startup.Main.getModuleSystem (Main.java:181)
    at org.netbeans.core.startup.Main.getModuleSystem (Main.java:150)
    at org.netbeans.core.startup.Main.start (Main.java:307)
    at org.netbeans.core.startup.TopThreadGroup.run(TopThreadGroup.java:123)
    at java.lang.Thread.run(Thread.java:745)
    Caused by: org.osgi.framework.BundleException: Exception in org.eclipse.osgi.framework.internal.core.SystemBundleActivator.start () of org.eclipse.osgi bundle.
    at org.eclipse.osgi.framework.internal.core.BundleContextImpl.startActivator(BundleContextImpl.java:734)
    at org.eclipse.osgi.framework.internal.core.BundleContextImpl.start(BundleContextImpl.java:683)
    at org.eclipse.osgi.framework.internal.core.InternalSystemBundle.resume(InternalSystemBundle.java:225)
    ... more than 17
    Caused by: java.lang.NumberFormatException: for input string: "2.0."
    at java.lang.NumberFormatException.forInputString(NumberFormatException.java:65)
    at java.lang.Integer.parseInt(Integer.java:492)
    at java.lang.Integer.parseInt(Integer.java:527)
    at org.eclipse.osgi.internal.resolver.StateBuilder.createBundleDescription(StateBuilder.java:61)
    at org.eclipse.osgi.internal.resolver.StateObjectFactoryImpl.createBundleDescription(StateObjectFactoryImpl.java:33)
    at org.eclipse.osgi.internal.baseadaptor.BaseStorage.readStateData(BaseStorage.java:845)
    at org.eclipse.osgi.internal.baseadaptor.BaseStorage.getStateManager(BaseStorage.java:791)
    at org.eclipse.osgi.baseadaptor.BaseAdaptor.getPlatformAdmin(BaseAdaptor.java:380)
    at org.eclipse.core.runtime.internal.adaptor.EclipseAdaptorHook.frameworkStart(EclipseAdaptorHook.java:90)
    at org.eclipse.osgi.baseadaptor.BaseAdaptor.frameworkStart(BaseAdaptor.java:253)
    at org.eclipse.osgi.framework.internal.core.SystemBundleActivator.start(SystemBundleActivator.java:60)
    to org.eclipse.osgi.framework.internal.core.BundleContextImpl$ 1.run(BundleContextImpl.java:711)
    at java.security.AccessController.doPrivileged (Native Method)
    at org.eclipse.osgi.framework.internal.core.BundleContextImpl.startActivator(BundleContextImpl.java:702)
    ... 19 more

    I already tried to reinstall ODI 12 c 12.1.3, but the error message is always the same. However, ODI-Studio run as superuser (known) does not work, even if the entire configuration is lost, for example repository connections.

    Sorry for the wall of text, I thought that some details could be useful. Someone at - it never have a similar problem? Is this a known issue? How can this problem be solved? I have found no information about it until now.

    Thanks in advance and greetings
    Thomas

    Remove the following the user-home directory:

    /. ODI/system12.1.3.0.0

    and try again.

    You will lose some preferences. But this shouuld not to be a problem.

  • Smart TPM D30 Linux kernel module?

    Seems that Linux does not recognize the TPM chip. There no module for it in the Linux kernel? I thought D30 supports RHEL6?

    Manufacturer: LENOVO
    Product name: 422916G
    Version: ThinkStation D30
    BIOS version: 0.37

    Sorry for the noise. The problem is resolved. You need to install the kernel-modules-extras package for the tpm_tis kernel module

  • Open/run multiple windows of the same VI

    Hello!

    In my current project, I would like to create a user open multiple windows of the same VI.  I made a re-entry VI:

    This is, actually, a very simple VI which has just a digital control, a loop and a stop button.  Then I have a VI that calls the VI re-entrant.  I would like it so that whenever the user presses the button "Call home VI", a new window of this VI is created and run.

    The first time the button is pressed, the reentrant VI opens and works very well. The title of the VI in the title bar is "Re - Entrant.vi:1 (clone)" (as expected).  When I try to launch another instance I get this error:

    I'm in LabVIEW 2009.

    Thanks for your time.

    I think you can do this with a static reference of VI, because it always points to the same instance of the VI (returning).

    You must open a new instance using Reference of VI open with option 0 x 08 (prepare environment run).

    Hope this helps,

    Daniel

  • Result of vulnerability analysis shows Sun Java JDK / JRE / SDK Multiple Vulnerabilities

    Analysis of vulnerabilities by Kaspersky Anti Virus showed Sun Java JDK / JRE / SDK Multiple vulnerabilities in my laptop Vista Home Basic 32-bit computer. Looking for solutions for

    In Kaspersky, if you click on the little details, it will bring up a full description of the possibility. It may look technically daunting, but generally if you scroll down there is a statement of how to fix the vulnerability. In most cases, it simply means updated the web browser plugin or program. In your case, it may simply mean Java update by visiting www.java.com and get the free update.

    Note that a vulnerability detected is not to say that your PC is infected with malware. It simply means that a security breach has been detected that could potentially be exploited by a person in certain circumstances.

  • Dblink Oracle to sql server, multiple database on the same server sql under a dblink

    Hi, we managed to set up an Oracle dblink to sql server and retrieve data.

    The user of sql server have been using via dblink has access to multiple databases on the same sql server

    But the question is how in oracle (if possible) prepend you the SQL access to this?

    For example:

    Sqlserver_prod has the user sqlserver_user which seems to be set up as default database sqlserver_db1

    But we have select access to sqlserver_db2

    all work well as sqlserver_user

    Select * from table_fromdb1

    Select * from dbo.table_fromdb1

    Select * from sqlserver_db1.dbo.table_fromdb1

    as does

    Select * from sqlserver_db2.dbo.table_fromdb2

    more in Oracle

    Oracle_db a dblink sqlserver_prod. World connection sqlserver_user

    everything works fine

    Select * from 'table_fromdb1"@sqlserver_prod '.

    Select * from 'dbo '. "table_fromdb1"@sqlserver_prod

    But how to (if possible) access from oracle

    sqlserver_db2.dbo.table_fromdb2

    without having to create a new sqlserver_db2_user referenced in a new dblink

    If oracle for oracle would be

    Select * from remote_oracle_schema.table@remote_oracle_db

    Hello

    You cannot select a table in a different SQL * database server from that to which the gateway instance connects.
    As stated in the documentation-

    Oracle® database gateway

    Installation and Configuration Guide

    11g Release 2 (11.2) for AIX 5 L Based Systems (64-bit), HP - UX

    Itanium, Solaris (SPARC 64-Bit), Linux x 86 operating system,

    and Linux x 86-64

    In the section.

    The example SQL Server multiple databases: Configuration of the modem router

    A separate instance of the gateway that is required for each SQL Server database. Each

    instance needs its own Gateway system ID (SID).

    ==========

    You will need to create a new instance of the gateway for the SQL * Server DB2 as well as a link separate db.

    Kind regards

    Mike

  • How can I select multiple items in the list of the spark without pressing the command?

    Hi all

    I need to change the behavioral list to allow multiple selections by clicking on each item

    In the list, instead of using the control

    30:

    Elazar r

    This blog explains how: http://flexponential.com/2009/12/13/multiple-selection-in-a-spark-list-without-the-control - key /

  • Connect to Oracle Server(windows 2003 Operating System) to the Linux server

    Hey,.
    I've been a job of Director Oracle for Computer Science Dept (at University).
    Part of my job is to install Oracle 11 g on a server that has windows 2003 System.next of operation is to connect to the Oracle server through the server.and of Linux and then create accounts to other students and grant privileges.



    I finished installing on the windows 2003 server.
    The next part, to connect to the Oracle server via the Linux server. I have access only to the Oracle (privileges) server but not on the Linux server.

    I'm unable to connect to the Oracle server via the Linux server.

    Could someone point me in the direction or recommend any hardware to connect to the Oracle server via the Linux server. Please I need help.
    Thank you.

    Published by: user12379367 on December 22, 2009 19:46

    >
    Thank you very much, I want to just connect to the server Linux Oracle database.
    But I couldn't connect to the Oracle Server Linux server using ssh.
    >

    SSH is not a technology allowing to connect to databases.

    You will need to install an Oracle client on the Linux server, implemented a tnsnames.ora file that includes the necessary connection information for the database of Windows Server.

    See the Linux 11 g Client install Guides here - http://www.oracle.com/pls/db111/portal.portal_db?selected=11&frame=

    Then read through the 11 g Net Services (http://download.oracle.com/docs/cd/B28359_01/network.111/b28316/toc.htm) Administrator's Guide for an overview of connectivity.

    HTH
    Srini

  • IPhone 7 will accept multiple fingerprints using the key ID?

    IPhone 7 will accept multiple fingerprints using the key ID?  If so, how?

    My iPhone 5 allows you to set up several fingerprints via settings > Touch ID & password, I doubt that the iPhone 7 would have fewer features.

    (I asked for your message to be moved to the forum from iPhone to help, do not know why you decided to post on the forum to help iPad.)

  • I use Thunderbird on multiple computers to the same gmail account but I have a laptop with little memory, so I need this laptop only to download a few files

    I use Thunderbird on multiple computers to the same gmail account. I have a small laptop with very little memory and it runs out of disk space when it downloads all my folders. I would only download some of my file on the laptop, but keep all the folder on my other computers because they do not have problems with disk space. When I unsubscribe records in 'manage folder subscriptions' then he cancels his subscription on all my computers, not just the laptop. When I go to 'Properties' on the folder and sets 'retention individual police' these settings are not applied at all. What can I do?

    All of the messages in each folder will appear in your message list. But this does not mean all the bodies of messages are downloaded, if you have properly configured the parameters of the disk. If what I described above stuck in your settings then Message body should be downloaded only 'on demand' when you click on each message.

    To confirm this install the addon glodaquilla, which has a column "on the disk" that indicates if a message is on the disk. If you want, after you have installed the addon set Thunderbird to work offline, so it does not download message body when you click in the list of messages.

  • Having multiple computers using the server POPS via Thunderbird. A new computer has IMAP server and cannot send or receive emails via Thunderbird. Help

    With the help of Mozilla Thunderbird - multiple computers use the POP server, but a new computer uses the IMAP server. Mail or back does not work
    Can we change the IMAP POP server to make it easier. All my other computers POP and mail is perfect.
    What can I do?

    First question is your email provider does support IMAP protocol?
    If this isn't the case, that is why it does not work.
    If they do, IMAP is a protocol much better use to check email from multiple devices.
    There are a lot of good tutorials on the differences between POP and IMAP if you can do your own research on this.

    You don't change an account from one protocol to another.
    You delete the account and add back with the correct protocol.
    Thunderbird has a tendency to select IMAP as a default value. You need to stop right there and make the POP changes if that's what you want or need.

  • How to switch between multiple windows in the same application?

    Hello

    I use OS X Capitan version 10.11.13 and I'm trying to find an easy way to switch between multiple windows in the same application by using CTRL + alt or different keys.

    Here is what I feel...

    Let's say I have Outlook, Google Chrome, Safari, iTunes and apps 'about this Mac' open.

    I open the new message window in Outlook and another Chrome window. I have therefore 2 separate windows in Outlook and Chrome.

    With that, I'm unable to move the composition and the window main outlook which is so annoying. Let's say I want to read the emails by the prospect main window and transfer of the content of the compose window! The command + tab doesn't take me to the main window of Microsoft outlook! Even if there were the last visited / applications window. This constraint is not intuitive, unless it can be configured in the settings?

    Strangely, I can't switch to the "about this Mac" window.

    The work around is to use the function (F3) mission button and click on the window, that I want to use or click the "Outlook" application on the dock icon and choose the window in the list.

    Does anyone know how switch between different windows in the same application by using a key combination or one another method other than listed above?

    Thank you

    Avinash

    In general, an Application that can open multiple windows provides a "Windows menu" you can choose the window you want.

  • I have TB on XP. I added a dual boot Linux Mint. Can I use the store XP documents with the Linux version of TB? TIA

    XP worked for years and has a lot of history and documents in folders of Thunderbird. Linux Mint has been installed on a different physical drive. Can I point the Linux of Thunderbird version to the XP data directory and use both XP and Linux versions of Thunderbird with a set of data files?

    I propose instead the full profile of Linux.

    http://KB.mozillazine.org/Moving_your_profile_folder_-_Thunderbird#Create_a_new_profile_and_copy_the_old_one_over_it

  • Multiple copies of the same mail and "unresponsive".

    I have fought with Thunderbird for about a week now and have had no chance to solve my problems. Any help would be greatly appreciated! I tried all the suggestions on the FAQ page.

    Here are my symptoms:
    -Make multiple copies of the same email with the same time stamp.
    -Not pulling new e-mail messages.
    -Whenever I try to navigate upwards or downwards in the Inbox or open an email TB will does not.
    -J' got warnings from the following script:
    Script: resource://gre/modules/XPCOMUtils.jsm:323
    Script: chrome://messenger/content/mailWindow.js:179

    Here is what I tried:
    -J' completely removed and reinstalled TB (and recovered my profile).
    -J' have compressed files.
    -J' rebuilt the database world.
    -From TB in safe mode does not seem to make a big difference.

    Fortunately, I have access to webmail via my ISP and it works fine.

    Thank you!

    McAfee has released a faulty update, please contact them for support on changing the setting to something that actually works.

    I saw a poster here today who used their support chat and they 'fixed a few adjustment' and now all is good.

    Not good was not what I wanted to say

  • Firefox does not work for multiple instances of the SAME user account on Windows Multipoint Server 2011

    We have a PC HP of MulitSeat MS6200
    It runs Microsoft Windows MultiPoint Server 2011 (which seems to be a twisted version of Windows 7)
    It is implemented in a laboratory of computer science and students connect you using their account for shared room - IE multiple instances of the same user accounts are currently running on the PC at the same time.
    The first student to run Firefox can work with it without a problem.
    However, when another student try to start firefox they get the following message:
    Firefox is already running but is not responding. To open a new window, you must first close the existing Firefox process, or restart your system.

    Cannot start Firefox using a profile that is already used by someone else.
    Each Firefox instance needs its own profile or you will get this error message.

    Use-no.-line switch remote control to open another instance of Firefox with its own profile and to different instances of Firefox running concurrently.

Maybe you are looking for