imPC@ndo IT

Tracker / CVE-2009-0518

CVE-2009-0518

Low 2.1

VI Client in VMware VirtualCenter before 2.5 Update 4, VMware ESXi 3.5 before Update 4, and VMware ESX 3.5 before Update 4 retains the VirtualCenter Server password in process memory, which might allow local users to obtain this password.

Affected products and versions

vmware vmware_esx
vmware vmware_esxi
vmware vmware_virtualcenter

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References