5

CVE-2009-3733

Directory traversal vulnerability in VMware Server 1.x before 1.0.10 build 203137 and 2.x before 2.0.2 build 203138 on Linux, VMware ESXi 3.5, and VMware ESX 3.0.3 and 3.5 allows remote attackers to read arbitrary files via unspecified vectors.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Esx Version 3.0.3
VMware ≫ Esx Version 3.5
VMware ≫ Esxi Version 3.5
VMware ≫ Server Version 1.0
VMware ≫ Server Version 1.0.1
VMware ≫ Server Version 1.0.1_build_29996
VMware ≫ Server Version 1.0.2
VMware ≫ Server Version 1.0.3
VMware ≫ Server Version 1.0.4
VMware ≫ Server Version 1.0.4_build_56528
VMware ≫ Server Version 1.0.5
VMware ≫ Server Version 1.0.6
VMware ≫ Server Version 1.0.7
VMware ≫ Server Version 1.0.8
VMware ≫ Server Version 1.0.9
VMware ≫ Server Version 2.0.0
   Linux ≫ Linux Kernel Version -
VMware ≫ Server Version 2.0.1
   Linux ≫ Linux Kernel Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 83.38% 0.996
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://security.gentoo.org/glsa/glsa-201209-25.xml
Third Party Advisory
http://lists.vmware.com/pipermail/security-announce/2009/000069.html
Patch
Vendor Advisory
http://www.securityfocus.com/archive/1/507523/100/0/threaded
Third Party Advisory
VDB Entry
http://www.vmware.com/security/advisories/VMSA-2009-0015.html
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2009/3062
Patch
Vendor Advisory
http://secunia.com/advisories/37186
Broken Link
http://securitytracker.com/id?1023088
Third Party Advisory
VDB Entry
http://securitytracker.com/id?1023089
Third Party Advisory
VDB Entry
http://www.securityfocus.com/bid/36842
Third Party Advisory
VDB Entry
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7822
Third Party Advisory