Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2006-3589 | First vendor Publication | 2006-07-21 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:N) | |||
---|---|---|---|
Cvss Base Score | 3.6 | Attack Range | Local |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 3.9 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-3589 |
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 1 | |
Application | 1 | |
Application | 1 | |
Application | 1 | |
Os | 7 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
27418 | VMware vmware-config.pl SSL Key File Permission Weakness VMware ESX Server, VMware GSX Server, VMware Player, VMware Server, and VMware Workstation utilize a flawed vmware-config.pl script that may lead to an unauthorized information disclosure. Under certain circumstances, the vmware-config.pl script may set weak file permissions on the SSL key used by VMware to encrypt console and management communications. If this key file is accessed by unauthorized users, it can be used to attack and decrypt the SSL communications of the affected VMware product, leading to a loss of confidentiality. This issue is not valid for VMware products running under the Windows operating system. |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:19:57 |
|
2024-11-28 12:09:29 |
|
2021-05-04 12:04:18 |
|
2021-04-22 01:04:56 |
|
2020-05-23 00:18:05 |
|
2018-10-31 00:19:46 |
|
2018-10-18 21:20:15 |
|
2017-07-20 09:23:44 |
|
2016-06-28 15:52:34 |
|
2016-04-26 14:51:28 |
|
2013-05-11 11:03:08 |
|