- ----------------------------------------------------------------------- Debian LTS Advisory DLA-3531-1 [email protected] https://www.debian.org/lts/security/ Utkarsh Gupta August 16, 2023 https://wiki.debian.org/LTS - ----------------------------------------------------------------------- Package : open-vm-tools Version : 2:10.3.10-1+deb10u4 CVE ID : CVE-2023-20867 Debian Bug : 1037546 open-vm-tools is a package that provides Open VMware Tools for virtual machines hosted on VMware. It was discovered that Open VM Tools incorrectly handled certain authentication requests. A fully compromised ESXi host can force Open VM Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. For Debian 10 buster, this problem has been fixed in version 2:10.3.10-1+deb10u4. We recommend that you upgrade your open-vm-tools packages. For the detailed security status of open-vm-tools please refer to its security tracker page at: https://security-tracker.debian.org/tracker/open-vm-tools Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS