-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-5493-1 [email protected] https://www.debian.org/security/ Moritz Muehlenhoff September 10, 2023 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : open-vm-tools CVE ID : CVE-2023-20867 CVE-2023-20900 Debian Bug : 1050970 Two security issues have been discovered in the Open VMware Tools, which may result in a man-in-the-middle attack or authentication bypass. For the oldstable distribution (bullseye), these problems have been fixed in version 2:11.2.5-2+deb11u2. For the stable distribution (bookworm), these problems have been fixed in version 2:12.2.0-1+deb12u1. We recommend that you upgrade your open-vm-tools packages. For the detailed security status of open-vm-tools please refer to its security tracker page at: https://security-tracker.debian.org/tracker/open-vm-tools Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: [email protected]