Advisories ยป MGASA-2024-0058

Updated open-vm-tools packages fix security vulnerabilities

Publication date: 14 Mar 2024
Modification date: 14 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-34058 , CVE-2023-34059

Description

The updated packages fix security vulnerabilities:
Authentication bypass vulnerability in the vgauth module.
(CVE-2023-20867)
SAML token signature bypass. (CVE-2023-34058)
File descriptor hijack vulnerability in the vmware-user-suid-wrapper.
(CVE-2023-34059)
                

References

SRPMS

9/core