CVE Vulnerabilities

CVE-2006-3589

Published: Jul 21, 2006 | Modified: Oct 30, 2018
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

Affected Software

Name Vendor Start Version End Version
Infrastructure Vmware 3 (including) 3 (including)
Player Vmware * *
Server Vmware 1.0.1_build_29996 (including) 1.0.1_build_29996 (including)
Workstation Vmware 5.5.3 (including) 5.5.3 (including)
Esx Vmware 2.0 (including) 2.0 (including)
Esx Vmware 2.0.1 (including) 2.0.1 (including)
Esx Vmware 2.1 (including) 2.1 (including)
Esx Vmware 2.1.1 (including) 2.1.1 (including)
Esx Vmware 2.1.2 (including) 2.1.2 (including)
Esx Vmware 2.5 (including) 2.5 (including)
Esx Vmware 2.5.2 (including) 2.5.2 (including)

References