VMWare TMP Directory License Information Vulnerability
BID:3119
Info
VMWare TMP Directory License Information Vulnerability
| Bugtraq ID: | 3119 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 30 2001 12:00AM |
| Updated: | Jul 30 2001 12:00AM |
| Credit: | This vulnerability was announced by starman jones <[email protected]> on July 30, 2001. |
| Vulnerable: |
VMWare VMWare 2.0 |
| Not Vulnerable: | |
Discussion
VMWare TMP Directory License Information Vulnerability
VMware is a Virtual Machine software package maintained and distributed by VMware, Incorporated.
VMware reveals sensitive information about it's users on a system. After installation and input of license data, VMware creates a file in /tmp with the name vmware-log.username, where username is the user of VMware. This file contains information about the user of VMware, including the VMware registration key.
VMware is a Virtual Machine software package maintained and distributed by VMware, Incorporated.
VMware reveals sensitive information about it's users on a system. After installation and input of license data, VMware creates a file in /tmp with the name vmware-log.username, where username is the user of VMware. This file contains information about the user of VMware, including the VMware registration key.
Exploit / POC
VMWare TMP Directory License Information Vulnerability
See discussion.
See discussion.
Solution / Fix
VMWare TMP Directory License Information Vulnerability
References
VMWare TMP Directory License Information Vulnerability
References:
References: