vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure...
Vulnerability Description
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2006-3589
Credits & Attribution
No credits recorded in the NVD database.
References
- http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html
- http://www.securityfocus.com/bid/19060
- http://secunia.com/advisories/23680
- http://secunia.com/advisories/21120
- http://securitytracker.com/id?1016536
- http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html
- http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html
- http://www.securityfocus.com/archive/1/440583/100/0/threaded
- http://www.vupen.com/english/advisories/2006/2880
- http://www.securityfocus.com/bid/19062
- http://www.securityfocus.com/archive/1/456546/100/200/threaded
- http://www.osvdb.org/27418
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27881
- http://kb.vmware.com/kb/2467205
- http://www.securityfocus.com/archive/1/441082/100/0/threaded
- http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html
More from vmware
View All →Affected Vendor
vmware
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.