« Back to list

CVE-2006-3589

Status: ModifiedLow (3.6)—

vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (5)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2006-3589",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 3.6,
          "accessVector": "LOCAL",
          "vectorString": "AV:L/AC:L/Au:N/C:P/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 4.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 3.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-07-21T14:03:00.000",
  "references": [
    {
      "url": "http://kb.vmware.com/kb/2467205",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/21120",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/23680",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securitytracker.com/id?1016536",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/27418",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/440583/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/441082/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/456546/100/200/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19060",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/19062",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2880",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27881",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://kb.vmware.com/kb/2467205",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/21120",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/23680",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securitytracker.com/id?1016536",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/27418",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/440583/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/441082/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/456546/100/200/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19060",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/19062",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx2/doc/esx-202-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx21/doc/esx-213-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-253-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vmware.com/support/esx25/doc/esx-254-200612-patch.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2880",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27881",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key."
    },
    {
      "lang": "es",
      "value": "vmware-config.pl en VMware for Linux, ESX Server 2.x, y Infrastructure 3 no valida el código de retorno desde la llamada a la función Perl chmod, lo cual podría permitir un fichero llave SSL sea creado con una umask no segura que permite a usuarios locales leer o modificar la llave SSL."
    }
  ],
  "lastModified": "2026-06-16T22:27:22.000",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:vmware:infrastructure:3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AD0E3A11-F411-4653-96ED-05ECE4DCF401"
            },
            {
              "criteria": "cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5A9A9E09-959A-4A99-A25C-09AA4FA646D5"
            },
            {
              "criteria": "cpe:2.3:a:vmware:server:1.0.1_build_29996:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EB051A5C-5F66-4732-949A-48B0FDE4AFF1"
            },
            {
              "criteria": "cpe:2.3:a:vmware:workstation:5.5.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7BA47458-E783-4A6A-ABF1-59E8D87E9B33"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A348CABB-CD52-4C55-9653-154C75605CD1"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BA74505A-3550-4646-B2D6-6E6D0924023D"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7632C2AE-4B59-4B17-8A6B-C1D05C2824FA"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EC77D81A-12AA-4948-9970-9461289DC648"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "54A10ABE-E778-4133-B1AA-05FE6829A34A"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C2CB97F9-9DF6-4493-A245-F4901F4DD22E"
            },
            {
              "criteria": "cpe:2.3:o:vmware:esx:2.5.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C862131A-64D8-4C2D-815F-19971D63AF00"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}