Mageia 2024-0058: open-vm-tools security update
Summary
The updated packages fix security vulnerabilities:
Authentication bypass vulnerability in the vgauth module.
(CVE-2023-20867)
SAML token signature bypass. (CVE-2023-34058)
File descriptor hijack vulnerability in the vmware-user-suid-wrapper.
(CVE-2023-34059)
References
- https://bugs.mageia.org/show_bug.cgi?id=32454
- https://access.redhat.com/errata/RHSA-2023:3948
- https://www.openwall.com/lists/oss-security/2023/10/27/1
- https://www.openwall.com/lists/oss-security/2023/10/27/2
- https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5
- https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/23678
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34058
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34059
Resolution
MGASA-2024-0058 - Updated open-vm-tools packages fix security vulnerabilities
SRPMS
- 9/core/open-vm-tools-12.3.5-2.mga9