Updated open-vm-tools packages fix security vulnerabilities
Publication date: 14 Mar 2024Modification date: 14 Mar 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-34058 , CVE-2023-34059
Description
The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. (CVE-2023-34059)
References
- https://bugs.mageia.org/show_bug.cgi?id=32454
- https://access.redhat.com/errata/RHSA-2023:3948
- https://www.openwall.com/lists/oss-security/2023/10/27/1
- https://www.openwall.com/lists/oss-security/2023/10/27/2
- https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5
- https://www.vmware.com/security/advisories/VMSA-2023-0024.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34058
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34059
SRPMS
9/core
- open-vm-tools-12.3.5-2.mga9