>> VMware "vmware-config.pl" Insecure SSL Key File Permissions Information Disclosure
Title : VMware "vmware-config.pl" Insecure SSL Key File Permissions Information Disclosure VUPEN ID : VUPEN/ADV-2006-2880 CVE ID : CVE-2006-3589
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2006-07-19
Technical Description
A vulnerability has been identified in VMware, which could be exploited by local attackers to disclose sensitive information. This flaw is due to an error in the "vmware-config.pl" script that sets permissions on the SSL key and certificate files without checking the return code generated by the "chmod()" call, which could cause the key file to be readable to any local user on the system.