Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

Mageia 9 MGASA-2024-0058 Critical: Open-VM-Tools Bypass Issues

mageia
Calendar Grey March 14, 2024
Dist Mageia Esm H88
The latest version of Mageia's open-vm-tools packages fixes severe security vulnerabilities that could leave users open to threats.
The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module

Summary

The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. (CVE-2023-34059)

References

- https://bugs.mageia.org/show_bug.cgi?id=32454

- https://access.redhat.com/errata/RHSA-2023:3948

- https://www.openwall.com/lists/oss-security/2023/10/27/1

- https://www.openwall.com/lists/oss-security/2023/10/27/2

- https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5

- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23678

- https://www.cve.org/CVERecord?id=CVE-2023-34058

- https://www.cve.org/CVERecord?id=CVE-2023-34059

Resolution

SRPMS

- 9/core/open-vm-tools-12.3.5-2.mga9

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 14 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0058.html
Type: security
CVE: CVE-2023-34058, CVE-2023-34059

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here