| Summary: | open-vm-tools new security issues CVE-2023-3405[89] | ||
|---|---|---|---|
| Product: | Mageia | Reporter: | Nicolas Salguero <nicolas.salguero> |
| Component: | Security | Assignee: | QA Team <qa-bugs> |
| Status: | RESOLVED FIXED | QA Contact: | Sec team <security> |
| Severity: | major | ||
| Priority: | Normal | CC: | andrewsfarm, herman.viaene, marja11, nicolas.salguero, smelror, sysadmin-bugs |
| Version: | 9 | Keywords: | advisory, validated_update |
| Target Milestone: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | MGA9-64-OK | ||
| Source RPM: | open-vm-tools-12.1.5-2.mga9.src.rpm | CVE: | CVE-2023-34058, CVE-2023-34059 |
| Status comment: | |||
| Bug Depends on: | |||
| Bug Blocks: | 32061 | ||
|
Description
Nicolas Salguero
2023-10-27 12:47:12 CEST
The fixes are given is the links above. Whiteboard:
(none) =>
MGA9TOO, MGA8TOO https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5 Status comment:
Patches available from upstream =>
Fixed upstream in 12.3.5 Assigning to the registered open-vm-tools maintainer CC:
(none) =>
marja11 Suggested advisory: ======================== The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. (CVE-2023-34059) References: https://access.redhat.com/errata/RHSA-2023:3948 https://www.openwall.com/lists/oss-security/2023/10/27/1 https://www.openwall.com/lists/oss-security/2023/10/27/2 https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5 https://www.vmware.com/security/advisories/VMSA-2023-0024.html ======================== Updated packages in core/updates_testing: ======================== open-vm-tools-12.3.5-2.mga9 open-vm-tools-desktop-12.3.5-2.mga9 open-vm-tools-devel-12.3.5-2.mga9 open-vm-tools-salt-minion-12.3.5-2.mga9 open-vm-tools-sdmp-12.3.5-2.mga9 open-vm-tools-test-12.3.5-2.mga9 from SRPM: open-vm-tools-12.3.5-2.mga9.src.rpm Status:
NEW =>
ASSIGNED
katnatek
2024-03-12 21:43:49 CET
Keywords:
(none) =>
advisory MGA9-64 Plasma Wayland on HP-Pavillion No installation issues. This laptop is not powerfull enough to run VMwaren so ref bug 30770, OK on clean install. Whiteboard:
(none) =>
MGA9-64-OK Validating. Keywords:
(none) =>
validated_update An update for this issue has been pushed to the Mageia Updates repository. https://advisories.mageia.org/MGASA-2024-0058.html Resolution:
(none) =>
FIXED |