RETIRED: VMware SSL Key File Information Disclosure Weakness
BID:19062
CVE-2006-3589 |Info
RETIRED: VMware SSL Key File Information Disclosure Weakness
| Bugtraq ID: | 19062 |
| Class: | Design Error |
| CVE: |
CVE-2006-3589 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 18 2006 12:00AM |
| Updated: | Jul 19 2006 06:02PM |
| Credit: | Nick Breese and security-assessment.com are credited with the discovery of this issue. |
| Vulnerable: |
VMWare Workstation for Linux 0 VMWare Server for Linux 0 VMWare Player for Linux 0 VMWare Infrastructure 3 VMWare ESX Server 2.5.2 VMWare ESX Server 2.5 VMWare ESX Server 2.1.2 VMWare ESX Server 2.1.1 VMWare ESX Server 2.1 VMWare ESX Server 2.0.1 build 6403 VMWare ESX Server 2.0.1 VMWare ESX Server 2.0 build 5257 VMWare ESX Server 2.0 |
| Not Vulnerable: | |
Discussion
RETIRED: VMware SSL Key File Information Disclosure Weakness
VMware is prone to a weakness that may allow attackers to gain access to SSL key files.
A local attacker could subsequently gain access to the key file and use this to disclose sensitive information, which may aid in carrying out other attacks.
This weakness only arises on Linux platforms.
This BID has been retired as it is a duplicate of BID 19060.
VMware is prone to a weakness that may allow attackers to gain access to SSL key files.
A local attacker could subsequently gain access to the key file and use this to disclose sensitive information, which may aid in carrying out other attacks.
This weakness only arises on Linux platforms.
This BID has been retired as it is a duplicate of BID 19060.
Exploit / POC
RETIRED: VMware SSL Key File Information Disclosure Weakness
An exploit is not required.
An exploit is not required.
Solution / Fix
RETIRED: VMware SSL Key File Information Disclosure Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]
References
RETIRED: VMware SSL Key File Information Disclosure Weakness
References:
References:
- VMware Homepage (VMware)
- VMSA-2006-0003 - VMware possible incorrect permissions on SSL key files (VMware Security Team
)