Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

Fedora 38: FEDORA-2023-df375d0634 Critical: Open-VM-Tools Security Issues

fedora
Calendar Grey September 14, 2023
Dist Fedora Esm H88
Important security vulnerabilities have been identified in the Open-VM-Tools update for Fedora 38, necessitating immediate attention and patching
Package new upstream version of open-vm-tools-12.3.0-22234872

Summary

The open-vm-tools project is an open source implementation of VMware Tools. It

is a suite of open source virtualization utilities and drivers to improve the

functionality, user experience and administration of VMware virtual machines.

This package contains only the core user-space programs and libraries of

open-vm-tools.

Update Information:

Package new upstream version of open-vm-tools-12.3.0-22234872. Security fix for CVE-2023-20900, CVE-2023-20867

Change Log

* Sat Sep 9 2023 John Wolfe - 12.3.0-1 - Package new upstream version of open-vm-tools-12.3.0-22234872. - Fix for CVE-2023-20900 - a SAML token signature bypass vulnerability. - Fix for CVE-2023-20867 - an Authentication Bypass vulnerability. - Linux quiesced snapshots have been updated to avoid intermittent hangs of the vmtoolsd process. - File systems prefrozen by custom quiescing scripts must be listed on the "excludedFileSystems" setting in the "vmbackup" section of the tools.conf file. - A tools.conf configuration setting is available to temporaily direct Linux quiesced snaphots to restore pre open-vm-tools 12.2.0 behavior of ignoring file systems already frozen. - A number of Coverity reported issues have been addressed. - A number of GitHub issues and pull requests have been handled. * Thu Jul 20 2023 Fedora Release Engineering - 12.1.5-4 - Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild

References


[ 1 ] Bug #2215553 - CVE-2023-20867 open-vm-tools: authentication bypass vulnerability in the vgauth module [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2215553 [ 2 ] Bug #2236578 - TRIAGE-CVE-2023-20900 open-vm-tools: SAML token signature bypass [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2236578 [ 3 ] Bug #2236603 - open-vm-tools version 12.3.0 has been released - please rebase https://bugzilla.redhat.com/show_bug.cgi?id=2236603

Update Instructions

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-df375d0634' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html

Severity
critical
Lowest
Low
Medium
High
Critical

Name: open-vm-tools
Product: Fedora 38
Version: 12.3.0
Release: 1.fc38
Summary: Open Virtual Machine Tools for virtual machines hosted on VMware

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here