Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2006-3589


vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.


Published

2006-07-21T14:03:00.000

Last Modified

2025-04-03T01:03:51.193

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 3.6 (LOW)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:P/I:P/A:N

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

3.9

Impact Score

4.9

Weaknesses
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application vmware infrastructure 3 Yes
Application vmware player * Yes
Application vmware server 1.0.1_build_29996 Yes
Application vmware workstation 5.5.3 Yes
Operating System vmware esx 2.0 Yes
Operating System vmware esx 2.0.1 Yes
Operating System vmware esx 2.1 Yes
Operating System vmware esx 2.1.1 Yes
Operating System vmware esx 2.1.2 Yes
Operating System vmware esx 2.5 Yes
Operating System vmware esx 2.5.2 Yes

References