Lucene search

K
cveMitreCVE-2006-3547
HistoryJul 13, 2006 - 12:05 a.m.

CVE-2006-3547

2006-07-1300:05:00
mitre
web.nvd.nist.gov
28
emc
vmware
player
dos
denial of service
ide1:0.filename
.vmx file
virtual machine
nvd
cve-2006-3547

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

AI Score

6.9

Confidence

High

EPSS

0.003

Percentile

70.3%

EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed

Affected configurations

Nvd
Node
vmwareplayer
VendorProductVersionCPE
vmwareplayer*cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:N/I:N/A:P

AI Score

6.9

Confidence

High

EPSS

0.003

Percentile

70.3%

Related for CVE-2006-3547