Lucene search

K
cve[email protected]CVE-2006-3589
HistoryJul 21, 2006 - 2:03 p.m.

CVE-2006-3589

2006-07-2114:03:00
web.nvd.nist.gov
23
vmware
linux
esx server
infrastructure 3
ssl key
umask
cve-2006-3589
nvd
security vulnerability

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.3%

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

Affected configurations

NVD
Node
vmwareinfrastructureMatch3
OR
vmwareplayer
OR
vmwareserverMatch1.0.1_build_29996
OR
vmwareworkstationMatch5.5.3
OR
vmwareesxMatch2.0
OR
vmwareesxMatch2.0.1
OR
vmwareesxMatch2.1
OR
vmwareesxMatch2.1.1
OR
vmwareesxMatch2.1.2
OR
vmwareesxMatch2.5
OR
vmwareesxMatch2.5.2

3.6 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:P/A:N

6.4 Medium

AI Score

Confidence

Low

0.001 Low

EPSS

Percentile

20.3%

Related for CVE-2006-3589