VMware ESX Multiple Information Disclosure Vulnerabilities
BID:19249
CVE-2006-2481 |Info
VMware ESX Multiple Information Disclosure Vulnerabilities
| Bugtraq ID: | 19249 |
| Class: | Design Error |
| CVE: |
CVE-2006-2481 CVE-2005-3620 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 31 2006 12:00AM |
| Updated: | Aug 01 2006 01:41PM |
| Credit: | Stephen de Vries and Martin O'Neal are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
VMWare ESX Server 2.5.2 VMWare ESX Server 2.5 VMWare ESX Server 2.1.2 VMWare ESX Server 2.1.1 VMWare ESX Server 2.1 VMWare ESX Server 2.0.2 VMWare ESX Server 2.0.1 build 6403 VMWare ESX Server 2.0.1 VMWare ESX Server 2.0 build 5257 VMWare ESX Server 2.0 |
| Not Vulnerable: |
VMWare ESX Server 2.5.3 Patch 2 VMWare ESX Server 2.5.2 Patch 4 VMWare ESX Server 2.1.3 Patch 1 VMWare ESX Server 2.0.2 Patch 1 |
Discussion
VMware ESX Multiple Information Disclosure Vulnerabilities
VMware ESX is prone to multiple information-disclosure vulnerabilities. These issues are due to a design error in the application. The following issues were reported:
1. An information disclosure vulnerability that could disclose the session ID, username, and password if an attacker can access session cookies used by the management interface.
2. An information disclosure vulnerability that could expose authentication credentials to local users on the computer hosting the VMWare ESX Server. This vulnerability occurs because authentication credentials are also handled insecurely by the VMWare ESX management interface.
VMware ESX server versions 2.5.3 P2, 2.1.3 P1, 2.0.2, 2.0.2 P1, and 2.5.2 P4 are reported to be vulnerable; other versions may also be affected.
VMware ESX is prone to multiple information-disclosure vulnerabilities. These issues are due to a design error in the application. The following issues were reported:
1. An information disclosure vulnerability that could disclose the session ID, username, and password if an attacker can access session cookies used by the management interface.
2. An information disclosure vulnerability that could expose authentication credentials to local users on the computer hosting the VMWare ESX Server. This vulnerability occurs because authentication credentials are also handled insecurely by the VMWare ESX management interface.
VMware ESX server versions 2.5.3 P2, 2.1.3 P1, 2.0.2, 2.0.2 P1, and 2.5.2 P4 are reported to be vulnerable; other versions may also be affected.
Exploit / POC
VMware ESX Multiple Information Disclosure Vulnerabilities
Attackers can exploit this issue using a web browser application.
The following sample URI has been provided:
Attackers can exploit this issue using a web browser application.
The following sample URI has been provided:
Solution / Fix
VMware ESX Multiple Information Disclosure Vulnerabilities
Solution:
The vendor has released VMware ESX versions 2.5.2 patch 4 and 2.0.2 to address these issues; please see the reference section for details.
Solution:
The vendor has released VMware ESX versions 2.5.2 patch 4 and 2.0.2 to address these issues; please see the reference section for details.
References
VMware ESX Multiple Information Disclosure Vulnerabilities
References:
References:
- VMware Homepage (VMware)
- Corsaire Security Advisory - VMware ESX Server Password Disclosure in Cookie iss ("advisories"
) - Corsaire Security Advisory - VMware ESX Server Password Disclosure in Log issue ("advisories"
) - VMSA-2006-0004 Cross site scripting vulnerability and other fixes (VMware Security Team
)