Knowledge Base

The VMware Knowledge Base provides support solutions, error messages and troubleshooting guides
 
Search the VMware Knowledge Base (KB)   View by Article ID
 

VMware Security Advisory VMSA-2006-0002: VMware Server Sensitive Information Lifetime Issue

Details

What is VMSA-2006-0002 VMware Server sensitive information lifetime issue?

Solution

VMware Security Advisory
Advisory ID:VMSA-2006-0002
Synopsis:VMware Server sensitive information lifetime issue
Advisory URL: http://www.vmware.com/support/kb/enduser/std_adp.php?p_faqid=2124
Issue date:2006-06-01
Updated on:2006-06-01
CVE Identifier:CVE-2006-2662

Summary

VMware Server doesn't limit the lifetime of sensitive data.

VMware has rated the severity of this issue as a Priority 3 issue according to VMware's Security Response Policy.

Relevant Release

VMware Server prior to RC1.

Problem Description

When a console connection is made using VMware Server, user credentials are kept in memory.

In order for the attacker to obtain information, he must have local access to the system and read access to the memory, or access to memory crash information.

This is only a danger if the attacker already has privileged access to your system.

The Common Vulnerabilities and Exposures (CVE) project has assigned the unique identifier CVE-2006-2662 to this issue.

Solution

Upgrade to the latest version of VMware Server. Download the packages at www.vmware.com/download/server/.

References

References specific to this security advisory include:

Also see the VMware Security Response Policy at www.vmware.com/support/policies/security_response.html.

Acknowledgments

VMware would like to thank Bart Vanautgaerden for reporting this issue.

Contact

Refer to www.vmware.com/security.

Keywords

2124; alertz; urls; CVE-2006-2662; 2124

Request a Product Feature

To request a new product feature or to provide feedback on a VMware product, please visit the Request a Product Feature page.

Feedback


Did this article help you?
This article resolved my issue.
This article did not resolve my issue.
This article helped but additional information was required to resolve my issue.
What can we do to improve this information? (4000 or fewer characters)
Actions