Description
VMware VirtualCenter 2.5 before Update 3 build 119838 on Windows displays a user's password in cleartext when the password contains unspecified special characters, which allows physically proximate attackers to steal the password.
Affected products
- VMware / virtualcenter2.5
- VMware / virtualcenter1.4.1 – 1.4.1
- VMware / virtualcenter2.0.1 – 2.0.1
- VMware / virtualcenter2.0.2 – 2.0.2
- VMware / virtualcenter2.0.2 – 2.0.2
- VMware / virtualcenter2.0.2 – 2.0.2
- VMware / virtualcenter2.0.2 – 2.0.2
- VMware / virtualcenter2.5 – 2.5
- VMware / virtualcenter2.5 – 2.5
References
- MAILING_LISThttp://marc.info/?l=bugtraq&m=122331139823057&w=2
- VENDOR_ADVISORYhttp://secunia.com/advisories/32179
- VENDOR_ADVISORYhttp://www.vupen.com/english/advisories/2008/2740
- MISChttp://www.securitytracker.com/id?1020992
- VENDOR_ADVISORYhttp://secunia.com/advisories/32180
- VENDOR_ADVISORYhttp://www.vmware.com/security/advisories/VMSA-2008-0016.html
- MISChttp://www.securityfocus.com/bid/31569
- MISChttps://exchange.xforce.ibmcloud.com/vulnerabilities/45664
- MISChttp://www.securityfocus.com/archive/1/497041/100/0/threaded