CVE-2006-3547
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/07/2006
Last modified:
03/04/2025
Description
EMC VMware Player allows user-assisted attackers to cause a denial of service (unrecoverable application failure) via a long value of the ide1:0.fileName parameter in the .vmx file of a virtual machine. NOTE: third parties have disputed this issue, saying that write access to the .vmx file enables other ways of stopping the virtual machine, so no privilege boundaries are crossed
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
2.60
Severity 2.0
LOW
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:vmware:player:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://www.osvdb.org/27524
- http://www.securityfocus.com/archive/1/437756/100/200/threaded
- http://www.securityfocus.com/archive/1/437806/100/200/threaded
- http://www.securityfocus.com/archive/1/437809/100/200/threaded
- http://www.osvdb.org/27524
- http://www.securityfocus.com/archive/1/437756/100/200/threaded
- http://www.securityfocus.com/archive/1/437806/100/200/threaded
- http://www.securityfocus.com/archive/1/437809/100/200/threaded



