MGASA-2024-0058 - Updated open-vm-tools packages fix security vulnerabilities

Publication date: 14 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0058.html
Type: security
Affected Mageia releases: 9
CVE: CVE-2023-34058,
     CVE-2023-34059

The updated packages fix security vulnerabilities:
Authentication bypass vulnerability in the vgauth module.
(CVE-2023-20867)
SAML token signature bypass. (CVE-2023-34058)
File descriptor hijack vulnerability in the vmware-user-suid-wrapper.
(CVE-2023-34059)

References:
- https://bugs.mageia.org/show_bug.cgi?id=32454
- https://access.redhat.com/errata/RHSA-2023:3948
- https://www.openwall.com/lists/oss-security/2023/10/27/1
- https://www.openwall.com/lists/oss-security/2023/10/27/2
- https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5
- https://www.vmware.com/security/advisories/VMSA-2023-0024.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34058
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34059

SRPMS:
- 9/core/open-vm-tools-12.3.5-2.mga9

Mageia 2024-0058: open-vm-tools security update

The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module

Summary

The updated packages fix security vulnerabilities: Authentication bypass vulnerability in the vgauth module. (CVE-2023-20867) SAML token signature bypass. (CVE-2023-34058) File descriptor hijack vulnerability in the vmware-user-suid-wrapper. (CVE-2023-34059)

References

- https://bugs.mageia.org/show_bug.cgi?id=32454

- https://access.redhat.com/errata/RHSA-2023:3948

- https://www.openwall.com/lists/oss-security/2023/10/27/1

- https://www.openwall.com/lists/oss-security/2023/10/27/2

- https://github.com/vmware/open-vm-tools/releases/tag/stable-12.3.5

- https://www.vmware.com/security/advisories/VMSA-2023-0024.html

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34058

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-34059

Resolution

MGASA-2024-0058 - Updated open-vm-tools packages fix security vulnerabilities

SRPMS

- 9/core/open-vm-tools-12.3.5-2.mga9

Severity
Publication date: 14 Mar 2024
URL: https://advisories.mageia.org/MGASA-2024-0058.html
Type: security
CVE: CVE-2023-34058, CVE-2023-34059

Related News