Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
Several security issues were fixed in Open VM Tools.. ========================================================================== Ubuntu Security Notice USN-7714-1 August 24, 2025 open-vm-tools vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 14.04 LTS Summary: Several security issues were fixed in Open VM Tools. Software Description: - open-vm-tools: Open VMware Tools for virtual machines hosted on VMware Details: Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059) Dolev Farhi discovered that Open VM Tools incorrectly handled certain file permissions. A local attacker could possibly use this issue to setup a symlink attack and override files without authorization. (CVE-2014-4199) Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 14.04 LTS open-vm-tools 2:9.4.0-1280544-5ubuntu6.4+esm1 Available with Ubuntu Pro open-vm-tools-desktop 2:9.4.0-1280544-5ubuntu6.4+esm1 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-7714-1 CVE-2014-4199, CVE-2023-34059 . The vulnerabilities in Open VM Tools on Ubuntu 14.04 LTS have been patched. Ensure you update your system to safeguard against potential local exploitation.. Ubuntu Security, Open VM Tools, Ubuntu Pro. . Severity: Critical. LinuxSecurity.com Team
Security fixes for CVE-2023-34058 and CVE-2023-34059. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-08e2bb6815 2023-11-08 01:38:49.724832 -------------------------------------------------------------------------------- Name : open-vm-tools Product : Fedora 38 Version : 12.3.0 Release : 3.fc38 URL : https://github.com/vmware/open-vm-tools Summary : Open Virtual Machine Tools for virtual machines hosted on VMware Description : The open-vm-tools project is an open source implementation of VMware Tools. It is a suite of open source virtualization utilities and drivers to improve the functionality, user experience and administration of VMware virtual machines. This package contains only the core user-space programs and libraries of open-vm-tools. -------------------------------------------------------------------------------- Update Information: Security fixes for CVE-2023-34058 and CVE-2023-34059 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 30 2023 John Wolfe - 12.3.0-3 - Address CVE-2023-34058 - BZ 2246963 - SAML token signature token bypass. - Address CVE-2023-34059 - BZ 2246962 - vmware-user-suid-wrapper file descriptor hijack vulnerability * Thu Oct 5 2023 Peter Robinson - 12.3.0-2 - Use fuse3 on new RHEL -------------------------------------------------------------------------------- References: [ 1 ] Bug #2246080 - CVE-2023-34058 open-vm-tools: SAML token signature bypass https://bugzilla.redhat.com/show_bug.cgi?id=2246080 [ 2 ] Bug #2246096 - CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper https://bugzilla.redhat.com/show_bug.cgi?id=2246096 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisoryFEDORA-2023-08e2bb6815' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Brief introduction CVE-2023-34058 . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3646-1
The updated packages fix a security vulnerability: An issue was discovered in dbus > = 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private . MGASA-2020-0262 - Updated dbus packages fix security vulnerability Publication date: 15 Jun 2020 URL: https://advisories.mageia.org/MGASA-2020-0262.html Type: security Affected Mageia releases: 7 CVE: CVE-2020-12049 The updated packages fix a security vulnerability: An issue was discovered in dbus > = 1.3.0 before 1.12.18. The DBusServer in libdbus, as used in dbus-daemon, leaks file descriptors when a message exceeds the per-message file descriptor limit. A local attacker with access to the D-Bus system bus or another system service's private AF_UNIX socket could use this to make the system service reach its file descriptor limit, denying service to subsequent D-Bus clients. (CVE-2020-12049) References: - https://bugs.mageia.org/show_bug.cgi?id=26735 - https://www.openwall.com/lists/oss-security/2020/06/04/3 - https://lists.debian.org/debian-lts-announce/2020/06/msg00003.html - https://www.cve.org/CVERecord?id=CVE-2020-12049 SRPMS: - 7/core/dbus-1.13.8-4.2.mga7 . Recent updates to the dbus packages have fixed a file descriptor leak issue that could impact service reliability. For further details, see MGASA-2020-0262. dbus Security Update, Mageia Advisory, File Descriptor Leak, Local Access Threat, Denial of Service. . Severity: Critical. LinuxSecurity.com Team
A vulnerability was found in the Bind DNS Server. Limits on simultaneous tcp connections have not been enforced correctly and could . Package : bind9 Version : 1:9.9.5.dfsg-9+deb8u18 CVE ID : CVE-2018-5743 A vulnerability was found in the Bind DNS Server. Limits on simultaneous tcp connections have not been enforced correctly and could lead to exhaustion of file descriptors. In the worst case this could affect the file descriptors of the whole system. For Debian 8 "Jessie", this problem has been fixed in version 1:9.9.5.dfsg-9+deb8u18. We recommend that you upgrade your bind9 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS . A critical connection exhaustion issue in Bind9 DNS Server on Debian requires immediate patching due to potential system impacts.. vulnerability, found, server, limits, simultaneous, connections. . Severity: Critical. LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for libu2f-host, pam_u2f ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1725-1 Rating: moderate References: #1128140 #1135727 #1135729 Cross-References: CVE-2019-12209 CVE-2019-12210 CVE-2019-9578 Affected Products: openSUSE Leap 15.0 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for libu2f-host and pam_u2f to version 1.0.8 fixes the following issues: Security issues fixed for libu2f-host: - CVE-2019-9578: Fixed a memory leak due to a wrong parse of init's response (bsc#1128140). Security issues fixed for pam_u2f: - CVE-2019-12209: Fixed an issue where symlinks in the user's directory were followed (bsc#1135729). - CVE-2019-12210: Fixed file descriptor leaks (bsc#1135727). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.0: zypper in -t patch openSUSE-2019-1725=1 Package List: - openSUSE Leap 15.0 (x86_64): libu2f-host-debuginfo-1.1.6-lp150.10.1 libu2f-host-debugsource-1.1.6-lp150.10.1 libu2f-host-devel-1.1.6-lp150.10.1 libu2f-host-doc-1.1.6-lp150.10.1 libu2f-host0-1.1.6-lp150.10.1 libu2f-host0-debuginfo-1.1.6-lp150.10.1 pam_u2f-1.0.8-lp150.7.1 pam_u2f-debuginfo-1.0.8-lp150.7.1 pam_u2f-debugsource-1.0.8-lp150.7.1 u2f-host-1.1.6-lp150.10.1 u2f-host-debuginfo-1.1.6-lp150.10.1 References: https://www.suse.com/security/cve/CVE-2019-12209.html https://www.suse.com/security/cve/CVE-2019-12210.html https://www.suse.com/security/cve/CVE-2019-9578.html https://bugzilla.suse.com/1128140 https://bugzilla.suse.com/1135727 https://bugzilla.suse.com/1135729 -- . This release tackles various bugs in libu2f-host and pam_u2f, improving overall security for openSUSE Leap 15.0.. openSUSE update, pam_u2f patch, libu2f-host fix, memory leak, security improvements. . LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available.. openSUSE Security Update: Security update for libu2f-host, pam_u2f ______________________________________________________________________________ Announcement ID: openSUSE-SU-2019:1708-1 Rating: moderate References: #1128140 #1135727 #1135729 Cross-References: CVE-2019-12209 CVE-2019-12210 CVE-2019-9578 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for libu2f-host and pam_u2f to version 1.0.8 fixes the following issues: Security issues fixed for libu2f-host: - CVE-2019-9578: Fixed a memory leak due to a wrong parse of init's response (bsc#1128140). Security issues fixed for pam_u2f: - CVE-2019-12209: Fixed an issue where symlinks in the user's directory were followed (bsc#1135729). - CVE-2019-12210: Fixed file descriptor leaks (bsc#1135727). This update was imported from the SUSE:SLE-15:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2019-1708=1 Package List: - openSUSE Leap 15.1 (x86_64): libu2f-host-debuginfo-1.1.6-lp151.2.6.1 libu2f-host-debugsource-1.1.6-lp151.2.6.1 libu2f-host-devel-1.1.6-lp151.2.6.1 libu2f-host-doc-1.1.6-lp151.2.6.1 libu2f-host0-1.1.6-lp151.2.6.1 libu2f-host0-debuginfo-1.1.6-lp151.2.6.1 pam_u2f-1.0.8-lp151.2.3.1 pam_u2f-debuginfo-1.0.8-lp151.2.3.1 pam_u2f-debugsource-1.0.8-lp151.2.3.1 u2f-host-1.1.6-lp151.2.6.1 u2f-host-debuginfo-1.1.6-lp151.2.6.1 References: https://www.suse.com/security/cve/CVE-2019-12209.html https://www.suse.com/security/cve/CVE-2019-12210.html https://www.suse.com/security/cve/CVE-2019-9578.html https://bugzilla.suse.com/1128140 https://bugzilla.suse.com/1135727 https://bugzilla.suse.com/1135729 -- . An openSUSE patch resolves bugs in libu2f-host and pam_u2f, tackling memory leaks and issues with symlinks.. openSUSE Updates, libu2f-host Fixes, pam_u2f Security, Update Instructions. . LinuxSecurity.com Team
An update that fixes three vulnerabilities is now available. . SUSE Security Update: Security update for libu2f-host, pam_u2f ______________________________________________________________________________ Announcement ID: SUSE-SU-2019:1750-1 Rating: moderate References: #1128140 #1135727 #1135729 Cross-References: CVE-2019-12209 CVE-2019-12210 CVE-2019-9578 Affected Products: SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SUSE Linux Enterprise Module for Basesystem 15-SP1 SUSE Linux Enterprise Module for Basesystem 15 ______________________________________________________________________________ An update that fixes three vulnerabilities is now available. Description: This update for libu2f-host and pam_u2f to version 1.0.8 fixes the following issues: Security issues fixed for libu2f-host: - CVE-2019-9578: Fixed a memory leak due to a wrong parse of init's response (bsc#1128140). Security issues fixed for pam_u2f: - CVE-2019-12209: Fixed an issue where symlinks in the user's directory were followed (bsc#1135729). - CVE-2019-12210: Fixed file descriptor leaks (bsc#1135727). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-SP1-2019-1750=1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15: zypper in -t patch SUSE-SLE-Module-Development-Tools-OBS-15-2019-1750=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2019-1750=1 -SUSE Linux Enterprise Module for Basesystem 15: zypper in -t patch SUSE-SLE-Module-Basesystem-15-2019-1750=1 Package List: - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15-SP1 (aarch64 ppc64le s390x x86_64): libu2f-host-debuginfo-1.1.6-3.6.1 libu2f-host-debugsource-1.1.6-3.6.1 libu2f-host-doc-1.1.6-3.6.1 u2f-host-1.1.6-3.6.1 u2f-host-debuginfo-1.1.6-3.6.1 - SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 (aarch64 ppc64le s390x x86_64): libu2f-host-debuginfo-1.1.6-3.6.1 libu2f-host-debugsource-1.1.6-3.6.1 libu2f-host-doc-1.1.6-3.6.1 u2f-host-1.1.6-3.6.1 u2f-host-debuginfo-1.1.6-3.6.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): libu2f-host-debuginfo-1.1.6-3.6.1 libu2f-host-debugsource-1.1.6-3.6.1 libu2f-host-devel-1.1.6-3.6.1 libu2f-host0-1.1.6-3.6.1 libu2f-host0-debuginfo-1.1.6-3.6.1 pam_u2f-1.0.8-3.3.1 pam_u2f-debuginfo-1.0.8-3.3.1 pam_u2f-debugsource-1.0.8-3.3.1 - SUSE Linux Enterprise Module for Basesystem 15 (aarch64 ppc64le s390x x86_64): libu2f-host-debuginfo-1.1.6-3.6.1 libu2f-host-debugsource-1.1.6-3.6.1 libu2f-host-devel-1.1.6-3.6.1 libu2f-host0-1.1.6-3.6.1 libu2f-host0-debuginfo-1.1.6-3.6.1 pam_u2f-1.0.8-3.3.1 pam_u2f-debuginfo-1.0.8-3.3.1 pam_u2f-debugsource-1.0.8-3.3.1 References: https://www.suse.com/security/cve/CVE-2019-12209.html https://www.suse.com/security/cve/CVE-2019-12210.html https://www.suse.com/security/cve/CVE-2019-9578.html https://bugzilla.suse.com/1128140 https://bugzilla.suse.com/1135727 https://bugzilla.suse.com/1135729 _______________________________________________ sle-security-updates mailing list
Get the latest Linux and open source security news straight to your inbox.