Vulnerability Name: | CVE-2008-3697 (CCN-44796) |
Assigned: | 2008-08-29 |
Published: | 2008-08-29 |
Updated: | 2018-10-11 |
Summary: | An unspecified ISAPI extension in VMware Server before 1.0.7 build 108231 allows remote attackers to cause a denial of service (IIS crash) via a malformed request.
|
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L)Exploitability Metrics: | Attack Vector (AV): Network Attack Complexity (AC): Low Privileges Required (PR): None User Interaction (UI): None | Scope: | Scope (S): Unchanged
| Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Low |
|
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Authentication (Au): None | Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P) 3.7 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P/E:U/RL:OF/RC:C)Exploitability Metrics: | Access Vector (AV): Network Access Complexity (AC): Low Athentication (Au): None
| Impact Metrics: | Confidentiality (C): None Integrity (I): None Availibility (A): Partial |
|
Vulnerability Type: | CWE-20
|
Vulnerability Consequences: | Denial of Service |
References: | Source: CCN Type: BugTraq Mailing List, Fri Aug 29 2008 - 19:08:36 CDT VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.
Source: MITRE Type: CNA CVE-2008-3697
Source: FULLDISC Type: UNKNOWN 20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.
Source: CCN Type: SA31708 VMware Server Multiple Vulnerabilities
Source: SECUNIA Type: Vendor Advisory 31708
Source: SREASON Type: UNKNOWN 4202
Source: CCN Type: SECTRACK ID: 1020789 VMware Server ISAPI Extension Bug Lets Remote Users Deny Service
Source: CCN Type: OSVDB ID: 48252 VMware Server Unspecified ISAPI Extension Malformed Request Remote DoS
Source: BUGTRAQ Type: UNKNOWN 20080830 VMSA-2008-0014 Updates to VMware Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.
Source: BID Type: UNKNOWN 30935
Source: CCN Type: BID-30935 VMware ISAPI Extension Remote Denial Of Service Vulnerability
Source: SECTRACK Type: UNKNOWN 1020789
Source: CCN Type: VMware Web site VMware: Virtualization via Hypervisor, Virtual Machine & Server Consolidation - VMware
Source: CONFIRM Type: UNKNOWN http://www.vmware.com/security/advisories/VMSA-2008-0014.html
Source: CONFIRM Type: UNKNOWN http://www.vmware.com/support/server/doc/releasenotes_server.html
Source: VUPEN Type: UNKNOWN ADV-2008-2466
Source: XF Type: UNKNOWN vmware-isapi-extension-dos(44796)
Source: XF Type: UNKNOWN vmware-isapi-extension-dos(44796)
|
Vulnerable Configuration: | Configuration 1: cpe:/a:vmware:server:1.0.1_build_29996:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.3:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.4_build_56528:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:1.0:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:1.0.0:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:1.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:1.0.2:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:1.0.4:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:1.0.5:*:*:*:*:*:*:*OR cpe:/a:vmware:vmware_server:*:*:*:*:*:*:*:* (Version <= 1.0.6) Configuration CCN 1: cpe:/a:vmware:server:1.0.1_build_29996:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.3:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.4_build_56528:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.1:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.2:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.4:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.5:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.7:*:*:*:*:*:*:*OR cpe:/a:vmware:server:1.0.6:*:*:*:*:*:*:* Denotes that component is vulnerable |
BACK |