Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2023-34059

Опубликовано: 27 окт. 2023
Источник: debian
EPSS Низкий

Описание

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
open-vm-toolsfixed2:12.3.5-1package

Примечания

  • https://www.openwall.com/lists/oss-security/2023/10/27/2

  • https://github.com/vmware/open-vm-tools/blob/CVE-2023-34059.patch/CVE-2023-34059.patch

  • https://www.openwall.com/lists/oss-security/2023/10/27/3

EPSS

Процентиль: 24%
0.00078
Низкий

Связанные уязвимости

CVSS3: 7.4
ubuntu
больше 1 года назад

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

CVSS3: 7.4
redhat
больше 1 года назад

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

CVSS3: 7.4
nvd
больше 1 года назад

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

CVSS3: 7
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 7.4
github
больше 1 года назад

open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.

EPSS

Процентиль: 24%
0.00078
Низкий