« Volver al listado

CVE-2006-3589

Estado: ModificadaBaja (3.6)—

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (5)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3589",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-07-21T14:03:00.000",
  "references": [
    {
      "url": "http://kb.vmware.com/kb/2467205",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/21120",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23680",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1016536",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/27418",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/440583/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/441082/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/456546/100/200/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19060",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19062",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2880",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27881",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://kb.vmware.com/kb/2467205",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/21120",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/23680",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1016536",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/27418",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/440583/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/441082/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/456546/100/200/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19060",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19062",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2880",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27881",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key."
    },
    {
      "lang": "es",
      "value": "vmware-config.pl en VMware for Linux, ESX Server 2.x, y Infrastructure 3 no valida el código de retorno desde la llamada a la función Perl chmod, lo cual podría permitir un fichero llave SSL sea creado con una umask no segura que permite a usuarios locales leer o modificar la llave SSL."
    }
  ],
  "lastModified": "2026-06-16T22:27:22.000",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:infrastructure:3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD0E3A11-F411-4653-96ED-05ECE4DCF401"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A9A9E09-959A-4A99-A25C-09AA4FA646D5"
            },
            {
              "criteria": "cpe:2.3:a:vmware:server:1.0.1_build_29996:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB051A5C-5F66-4732-949A-48B0FDE4AFF1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:5.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BA47458-E783-4A6A-ABF1-59E8D87E9B33"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A348CABB-CD52-4C55-9653-154C75605CD1"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA74505A-3550-4646-B2D6-6E6D0924023D"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7632C2AE-4B59-4B17-8A6B-C1D05C2824FA"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC77D81A-12AA-4948-9970-9461289DC648"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54A10ABE-E778-4133-B1AA-05FE6829A34A"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2CB97F9-9DF6-4493-A245-F4901F4DD22E"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C862131A-64D8-4C2D-815F-19971D63AF00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}