CVE Vulnerabilities

CVE-2006-3589

Published: Jul 21, 2006 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.6 LOW
AV:L/AC:L/Au:N/C:P/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

Affected Software

NameVendorStart VersionEnd Version
InfrastructureVmware3 (including)3 (including)
PlayerVmware**
ServerVmware1.0.1_build_29996 (including)1.0.1_build_29996 (including)
WorkstationVmware5.5.3 (including)5.5.3 (including)
EsxVmware2.0 (including)2.0 (including)
EsxVmware2.0.1 (including)2.0.1 (including)
EsxVmware2.1 (including)2.1 (including)
EsxVmware2.1.1 (including)2.1.1 (including)
EsxVmware2.1.2 (including)2.1.2 (including)
EsxVmware2.5 (including)2.5 (including)
EsxVmware2.5.2 (including)2.5.2 (including)

References