CVE Vulnerabilities

CVE-2011-1789

Published: May 09, 2011 | Modified: May 26, 2011
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The self-extracting installer in the vSphere Client Installer package in VMware vCenter 4.0 before Update 3 and 4.1 before Update 1, VMware ESXi 4.x before 4.1 Update 1, and VMware ESX 4.x before 4.1 Update 1 does not have a digital signature, which might make it easier for remote attackers to spoof the software distribution via a Trojan horse installer.

Affected Software

Name Vendor Start Version End Version
Esx Vmware 4.0 (including) 4.0 (including)
Esx Vmware 4.1 (including) 4.1 (including)
Esxi Vmware 4.0 (including) 4.0 (including)
Esxi Vmware 4.1 (including) 4.1 (including)
Vcenter Vmware 4.0 (including) 4.0 (including)
Vcenter Vmware 4.0-update_1 (including) 4.0-update_1 (including)
Vcenter Vmware 4.0-update_2 (including) 4.0-update_2 (including)
Vcenter Vmware 4.1 (including) 4.1 (including)

References