An update for open-vm-tools is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ===================================================================== Red Hat Security Advisory Synopsis: Important: open-vm-tools security update Advisory ID: RHSA-2023:5217-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2023:5217 Issue date: 2023-09-19 CVE Names: CVE-2023-20900 ===================================================================== 1. Summary: An update for open-vm-tools is now available for Red Hat Enterprise Linux 7. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Client (v. 7) - x86_64 Red Hat Enterprise Linux Client Optional (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode (v. 7) - x86_64 Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64 Red Hat Enterprise Linux Server (v. 7) - x86_64 Red Hat Enterprise Linux Server Optional (v. 7) - x86_64 Red Hat Enterprise Linux Workstation (v. 7) - x86_64 Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64 3. Description: The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines. Security Fix(es): * open-vm-tools: SAML token signature bypass (CVE-2023-20900) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to theCVE page(s) listed in the References section. 4. Solution: Before applying this update, make sure all previously released errata relevant to your system have been applied. For details on how to apply this update, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 2236542 - CVE-2023-20900 open-vm-tools: SAML token signature bypass 6. Package List: Red Hat Enterprise Linux Client (v. 7): Source: open-vm-tools-11.0.5-3.el7_9.7.src.rpm x86_64: open-vm-tools-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-desktop-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Client Optional (v. 7): x86_64: open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-devel-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-test-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux ComputeNode (v. 7): Source: open-vm-tools-11.0.5-3.el7_9.7.src.rpm x86_64: open-vm-tools-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-desktop-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux ComputeNode Optional (v. 7): x86_64: open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-devel-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-test-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Server (v. 7): Source: open-vm-tools-11.0.5-3.el7_9.7.src.rpm x86_64: open-vm-tools-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-desktop-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Server Optional (v. 7): x86_64: open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-devel-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-test-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux Workstation (v. 7): Source: open-vm-tools-11.0.5-3.el7_9.7.src.rpm x86_64: open-vm-tools-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-desktop-11.0.5-3.el7_9.7.x86_64.rpm Red Hat Enterprise Linux WorkstationOptional (v. 7): x86_64: open-vm-tools-debuginfo-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-devel-11.0.5-3.el7_9.7.x86_64.rpm open-vm-tools-test-11.0.5-3.el7_9.7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key 7. References: https://access.redhat.com/security/cve/CVE-2023-20900 https://access.redhat.com/security/updates/classification#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact Copyright 2023 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIcBAEBCAAGBQJlCWlmAAoJENzjgjWX9erEPS8P/i8WPrzZQO9inFCO+eay+rbA VeU/qq1n87Hn0p6M1hGsgiuAHLbZRUDQXamcUIO3bR5UzOv4ZRyYJclDKBtEIlRS LIZ/ABag717I5GeZsAavy8/xwLWExsteuq/7StmayaCmNpdKukR6ufVrfXD8K7oq hEIiX/PLEZi8qF+aITUs8naZNOWDwXv3afDXFRXtlB77o/s2hzDnDi1HrqrNmgnA UpGHUfMvK81EWMgSdpOljYzamEqPUF3sGiz4KyCP3vsF/BQvFRMpYzmcAbAj0rUX QwZzxf5z9qKcXwgnH/gOPd14lpjxvDSEpgB5DlwkqtIg3FBLYSlTBLoNJPT3RhnC uOuiMr+jMOUGzutxBYPVqyHWU+Q7o0rT7xzDzz/iyu8fMDrttM0ZRz9wudBwv3iL r7hVgVMyIqox8jnAMzqmZfyoAHamCleOQxoyTlhHz/RubSO/DlTIuehd2ynIaX1u YXYoTbUr3yykoLmGufNura5PUbYWOc7C3501vqaJvKSv6k4sCDT4wcEvLu/wjZho KyaJjJInE2J0MkS89sup9lgJx3AWa7eBdin6iuwPwxn46jx8+xukpzVBfsMZDp10 wkYZzR7bVsVOEcU+xoKIjLib1k3BT9GwKAVeqjstG3lQrG83xY31xCk6c9AHKLVk /8t3XWkz1U6HaPaNqbYT =WsFm -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Package new upstream version of open-vm-tools-12.3.0-22234872. Security fix for CVE-2023-20900, CVE-2023-20867. -------------------------------------------------------------------------------- Fedora Update Notification FEDORA-2023-20b6ac4b6c 2023-09-15 18:36:13.242774 -------------------------------------------------------------------------------- Name : open-vm-tools Product : Fedora 39 Version : 12.3.0 Release : 1.fc39 URL : https://github.com/vmware/open-vm-tools Summary : Open Virtual Machine Tools for virtual machines hosted on VMware Description : The open-vm-tools project is an open source implementation of VMware Tools. It is a suite of open source virtualization utilities and drivers to improve the functionality, user experience and administration of VMware virtual machines. This package contains only the core user-space programs and libraries of open-vm-tools. -------------------------------------------------------------------------------- Update Information: Package new upstream version of open-vm-tools-12.3.0-22234872. Security fix for CVE-2023-20900, CVE-2023-20867 -------------------------------------------------------------------------------- ChangeLog: * Sat Sep 9 2023 John Wolfe - 12.3.0-1 - Package new upstream version of open-vm-tools-12.3.0-22234872. - Fix for CVE-2023-20900 - a SAML token signature bypass vulnerability. - Fix for CVE-2023-20867 - an Authentication Bypass vulnerability. - Linux quiesced snapshots have been updated to avoid intermittent hangs of the vmtoolsd process. - File systems prefrozen by custom quiescing scripts must be listed on the "excludedFileSystems" setting in the "vmbackup" section of the tools.conf file. - A tools.conf configuration setting is available to temporaily direct Linux quiesced snaphots to restore pre open-vm-tools 12.2.0 behavior of ignoring file systems already frozen. - A number of Coverity reported issues have beenaddressed. - A number of GitHub issues and pull requests have been handled. -------------------------------------------------------------------------------- References: [ 1 ] Bug #2215553 - CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2215553 [ 2 ] Bug #2236578 - TRIAGE-CVE-2023-20900 open-vm-tools: SAML token signature bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236578 [ 3 ] Bug #2236603 - open-vm-tools version 12.3.0 has been released - please rebase https://bugzilla.redhat.com/show_bug.cgi?id=2236603 -------------------------------------------------------------------------------- This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-20b6ac4b6c' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ -------------------------------------------------------------------------------- _______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.