The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. . MGASA-2024-0058 - Updated open-vm-tools packages fix security vulnerabilities Publication date: 14 Mar 2024 URL: https://advisories.mageia.org/MGASA-2024-0058.html Type: security Affected Mageia releases: 9 CVE: CVE-2023-34058, CVE-2023-34059 The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. (CVE-2023-34059) References: - https://bugs.mageia.org/show_bug.cgi?id=32454 - https://access.redhat.com/errata/RHSA-2023:3948 - https://www.openwall.com/lists/oss-security/2023/10/27/1 - https://www.openwall.com/lists/oss-security/2023/10/27/2 - https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5 - https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23678 - https://www.cve.org/CVERecord?id=CVE-2023-34058 - https://www.cve.org/CVERecord?id=CVE-2023-34059 SRPMS: - 9/core/open-vm-tools-12.3.5-2.mga9 . The latest version of Mageia's open-vm-tools packages fixes severe security vulnerabilities that could leave users open to threats.. open-vm-tools security fix,Mageia packages update,authentication flaws,security vulnerabilities. . Severity: Critical. LinuxSecurity.com Team
The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: . Oracle Linux Security Advisory ELSA-2023-7265 https://linux.oracle.com/errata/ELSA-2023-7265.html The following updated rpms for Oracle Linux 8 have been uploaded to the Unbreakable Linux Network: x86_64: open-vm-tools-12.2.5-3.0.1.el8_9.1.x86_64.rpm open-vm-tools-desktop-12.2.5-3.0.1.el8_9.1.x86_64.rpm open-vm-tools-salt-minion-12.2.5-3.0.1.el8_9.1.x86_64.rpm open-vm-tools-sdmp-12.2.5-3.0.1.el8_9.1.x86_64.rpm SRPMS: https://oss.oracle.com:443/ol8/SRPMS-updates//open-vm-tools-12.2.5-3.0.1.el8_9.1.src.rpm Related CVEs: CVE-2023-34058 CVE-2023-34059 Description of changes: [12.2.5-3.0.1.1] - Fix CVE-2023-34058 open-vm-tools: SAML token signature bypass - Fix CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper [12.2.5-3.0.1] - Fix spaces in vmware udev rule for scsi devices [Orabug: 24461968] - Fix vmware udev rule in 99-vmware-scsi-timeout.rules file. [Orabug: 22815019] - Increase timeout for scsi devices on VMWare guests by adding a udev rule. [Orabug: 21819156] _______________________________________________ El-errata mailing list
Security fixes for CVE-2023-34058 and CVE-2023-34059. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-86a50ffc72 2023-11-08 01:25:18.668446 -------------------------------------------------------------------------------- Name : open-vm-tools Product : Fedora 39 Version : 12.3.0 Release : 3.fc39 URL : https://github.com/vmware/open-vm-tools Summary : Open Virtual Machine Tools for virtual machines hosted on VMware Description : The open-vm-tools project is an open source implementation of VMware Tools. It is a suite of open source virtualization utilities and drivers to improve the functionality, user experience and administration of VMware virtual machines. This package contains only the core user-space programs and libraries of open-vm-tools. -------------------------------------------------------------------------------- Update Information: Security fixes for CVE-2023-34058 and CVE-2023-34059 -------------------------------------------------------------------------------- ChangeLog: * Mon Oct 30 2023 John Wolfe - 12.3.0-3 - Address CVE-2023-34058 - BZ 2246963 - SAML token signature token bypass. - Address CVE-2023-34059 - BZ 2246962 - vmware-user-suid-wrapper file descriptor hijack vulnerability -------------------------------------------------------------------------------- References: [ 1 ] Bug #2246080 - CVE-2023-34058 open-vm-tools: SAML token signature bypass https://bugzilla.redhat.com/show_bug.cgi?id=2246080 [ 2 ] Bug #2246096 - CVE-2023-34059 open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper https://bugzilla.redhat.com/show_bug.cgi?id=2246096 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-86a50ffc72' at the command line. For more information, refer to the dnfdocumentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.