Описание
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1
Одно из
cpe:2.3:a:vmware:infrastructure:3:*:*:*:*:*:*:*
cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:*
cpe:2.3:a:vmware:server:1.0.1_build_29996:*:*:*:*:*:*:*
cpe:2.3:a:vmware:workstation:5.5.3:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.0:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.0.1:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.1:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.1.1:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.1.2:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.5:*:*:*:*:*:*:*
cpe:2.3:o:vmware:esx:2.5.2:*:*:*:*:*:*:*
EPSS
Процентиль: 21%
0.00066
Низкий
3.6 Low
CVSS2
Дефекты
NVD-CWE-Other
Связанные уязвимости
github
почти 4 года назад
vmware-config.pl in VMware for Linux, ESX Server 2.x, and Infrastructure 3 does not check the return code from a Perl chmod function call, which might cause an SSL key file to be created with an unsafe umask that allows local users to read or modify the SSL key.
EPSS
Процентиль: 21%
0.00066
Низкий
3.6 Low
CVSS2
Дефекты
NVD-CWE-Other