Red Hat Enterprise Linux 4
Red Hat Enterprise Linux 4
The Red Hat Enterprise Linux 4 reached end of service life on Mar 31, 2017 — Red Hat no longer ships security patches or fixes for it. Our third-party support keeps it safe to run: 24/7 engineers manage issues, remediate vulnerabilities, and help you maintain compliance.
24/7 engineers own your Red Hat Enterprise Linux 4 incidents end to end.
Mitigation and patch-around guidance when the vendor no longer ships fixes.
Controls evidence and documentation that keep auditors satisfied.
Specifications
- product
- rhel
- release
- 4
- product Label
- Red Hat Enterprise Linux
- release Label
- 4
- codename
- lts
- latest Version
- 4.9
- release Date
- 2005-02-15
- maintained
- source Url
- https://endoflife.date/rhel
Lifecycle Dates
- End of Service Life
- Mar 31, 2017
- Last OEM Support
- Mar 31, 2009
OEM vs. 3rd Party Support
See how third-party support compares to the vendor contract for Red Hat Enterprise Linux 4 — monitoring, break/fix, vulnerability work, operations and compliance, before and after EOSL.
| Feature | OEM Support | 3rd Party Support |
|---|---|---|
| Post-EOSL Support | ||
| Break/Fix Support | Until EOSL | |
| 24/7 Monitoring | ||
| Vulnerability Scanning & Remediation | ||
| Managed Operations | ||
| Procedure & Configuration Review | ||
| Compliance & Audit Documentation | Limited | |
| Discounted Migration to Other Platforms |
Why Choose 3rd Party Support for Red Hat Enterprise Linux 4?
Vulnerability Remediation
Scanning, mitigation and patch-around guidance for Red Hat Enterprise Linux 4 when the vendor no longer ships fixes.
Compliance Maintenance
Procedure review, controls evidence and the documentation auditors ask for — maintained continuously, not scrambled at audit time.
24/7 Expert Support
Engineers who know this release monitor, manage and fix issues around the clock — break/fix to managed operations.
Red Hat Enterprise Linux 4 Support: Frequently Asked Questions
Is the Red Hat Enterprise Linux 4 still supported?
Red Hat ended support for the Red Hat Enterprise Linux 4 on Mar 31, 2017 — no more patches or fixes from the vendor. Third-party support keeps it covered: our engineers manage issues, remediate vulnerabilities, and help you maintain compliance for as long as you run it.
When is the Red Hat Enterprise Linux 4 end of service life (EOSL) date?
Red Hat lists the end of service life for the Red Hat Enterprise Linux 4 as Mar 31, 2017.
Can I keep using the Red Hat Enterprise Linux 4 after its EOSL date?
Yes. EOSL means Red Hat stops issuing patches and support — the software itself keeps running. Third-party support covers it from there: issue management, security vulnerability remediation, and the compliance documentation auditors ask for, for as long as you choose to run it.
How much does third-party support for the Red Hat Enterprise Linux 4 cost?
Typically 40-70% below the OEM maintenance renewal price. Exact pricing depends on quantity, service level and location — request a quote and we respond within 24 hours.
Known Vulnerabilities Affecting Red Hat Enterprise Linux 4
84 published CVEs affect the Red Hat Enterprise Linux 4, including 37 rated critical or high severity. Red Hat no longer ships security patches for this release — our engineers provide mitigation guidance, workarounds and hardening support.
| CVE | Severity | CVSS | Published | Summary |
|---|---|---|---|---|
| CVE-2011-2717 | CRITICAL | 9.8 | Nov 27, 2019 | The DHCPv6 client (dhcp6c) as used in the dhcpv6 project through 2011-07-25 allows remote DHCP servers to execute arbitrary commands via shell metacharacters in a hostname obtained from a DHCP message. |
| CVE-2011-2897 | CRITICAL | 9.8 | Nov 12, 2019 | gdk-pixbuf through 2.31.1 has GIF loader buffer overflow when initializing decompression tables due to an input validation flaw |
| CVE-2014-7169 | CRITICAL | 9.8 | Sep 25, 2014 | GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occu |
| CVE-2014-6271 | CRITICAL | 9.8 | Sep 24, 2014 | GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "Sh |
| CVE-2011-3188 | CRITICAL | 9.1 | May 24, 2012 | The (1) IPv4 and (2) IPv6 implementations in the Linux kernel before 3.1 use a modified MD4 algorithm to generate sequence numbers and Fragment Identification values, which makes it easier for remote attackers to cause a denial of service (disrupted networking) or hijack network sessions by predicting these values and sending crafted packets. |
| CVE-2009-0846 | HIGH | 10.0 | Apr 9, 2009 | The asn1_decode_generaltime function in lib/krb5/asn.1/asn1_decode.c in the ASN.1 GeneralizedTime decoder in MIT Kerberos 5 (aka krb5) before 1.6.4 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via vectors involving an invalid DER encoding that triggers a free of an uninitialized pointer. |
| CVE-2007-1007 | HIGH | 10.0 | Feb 20, 2007 | Format string vulnerability in GnomeMeeting 1.0.2 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via format strings in the name, which is not properly handled in a call to the gnomemeeting_log_insert function. |
| CVE-2006-6235 | HIGH | 10.0 | Dec 7, 2006 | A "stack overwrite" vulnerability in GnuPG (gpg) 1.x before 1.4.6, 2.x before 2.0.2, and 1.9.0 through 1.9.95 allows attackers to execute arbitrary code via crafted OpenPGP packets that cause GnuPG to dereference a function pointer from deallocated stack memory. |
| CVE-2005-3625 | HIGH | 10.0 | Dec 31, 2005 | Xpdf, as used in products such as gpdf, kpdf, pdftohtml, poppler, teTeX, CUPS, libextractor, and others, allows attackers to cause a denial of service (infinite loop) via streams that end prematurely, as demonstrated using the (1) CCITTFaxDecode and (2) DCTDecode streams, aka "Infinite CPU spins." |
| CVE-2011-3191 | HIGH | 8.8 | May 24, 2012 | Integer signedness error in the CIFSFindNext function in fs/cifs/cifssmb.c in the Linux kernel before 3.1 allows remote CIFS servers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a large length value in a response to a read request for a directory. |
| CVE-2007-1351 | HIGH | 8.5 | Apr 6, 2007 | Integer overflow in the bdfReadCharacters function in bdfread.c in (1) X.Org libXfont before 20070403 and (2) freetype 2.3.2 and earlier allows remote authenticated users to execute arbitrary code via crafted BDF fonts, which result in a heap overflow. |
| CVE-2011-1145 | HIGH | 7.8 | Nov 14, 2019 | The SQLDriverConnect() function in unixODBC before 2.2.14p2 have a possible buffer overflow condition when specifying a large value for SAVEFILE parameter in the connection string. |
| CVE-2005-4890 | HIGH | 7.8 | Nov 4, 2019 | There is a possible tty hijacking in shadow 4.x before 4.1.5 and sudo 1.x before 1.7.4 via "su - user -c program". The user session can be escaped to the parent session by using the TIOCSTI ioctl to push characters into the input buffer to be read by the next process. |
| CVE-2012-1097 | HIGH | 7.8 | May 17, 2012 | The regset (aka register set) feature in the Linux kernel before 3.2.10 does not properly handle the absence of .get and .set methods, which allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a (1) PTRACE_GETREGSET or (2) PTRACE_SETREGSET ptrace call. |
| CVE-2011-2525 | HIGH | 7.8 | Feb 2, 2012 | The qdisc_notify function in net/sched/sch_api.c in the Linux kernel before 2.6.35 does not prevent tc_fill_qdisc function calls referencing builtin (aka CQ_F_BUILTIN) Qdisc structures, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) or possibly have unspecified other impact via a crafted call. |
| CVE-2011-4967 | HIGH | 7.5 | Nov 19, 2019 | tog-Pegasus has a package hash collision DoS vulnerability |
| CVE-2019-0217 | HIGH | 7.5 | Apr 8, 2019 | In Apache HTTP Server 2.4 release 2.4.38 and prior, a race condition in mod_auth_digest when running in a threaded server could allow a user with valid credentials to authenticate using another username, bypassing configured access control restrictions. |
| CVE-2011-2699 | HIGH | 7.5 | May 24, 2012 | The IPv6 implementation in the Linux kernel before 3.1 does not generate Fragment Identification values separately for each destination, which makes it easier for remote attackers to cause a denial of service (disrupted networking) by predicting these values and sending crafted packets. |
| CVE-2010-4805 | HIGH | 7.5 | May 26, 2011 | The socket implementation in net/core/sock.c in the Linux kernel before 2.6.35 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service by sending a large amount of network traffic, related to the sk_add_backlog function and the sk_rmem_alloc socket field. NOTE: this vulnerability exists because of an incomplete fix for CVE-2010-4251. |
| CVE-2010-4251 | HIGH | 7.5 | May 26, 2011 | The socket implementation in net/core/sock.c in the Linux kernel before 2.6.34 does not properly manage a backlog of received packets, which allows remote attackers to cause a denial of service (memory consumption) by sending a large amount of network traffic, as demonstrated by netperf UDP tests. |
Showing the 20 most severe of 84 known CVEs.
Get Third Party SupportRelated Red Hat Products
All Red Hat products →Red Hat Enterprise Linux 9 (Upcoming ELS)
EOSL: May 31, 2036
Red Hat Enterprise Linux 8 (Upcoming ELS)
EOSL: May 31, 2033
Red Hat Enterprise Linux 10 (Upcoming ELS)
EOSL: May 31, 2039
Red Hat Enterprise Linux 6 (ELS)
EOSL: Jun 30, 2024
Red Hat Enterprise Linux 5 (ELS)
EOSL: Nov 30, 2020
Red Hat Enterprise Linux 7 (ELS)
EOSL: May 31, 2029