Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

rocky логотип

RLSA-2023:7265

Опубликовано: 28 нояб. 2023
Источник: rocky
Оценка: Important

Описание

Important: open-vm-tools security update

The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines.

Security Fix(es):

  • open-vm-tools: SAML token signature bypass (CVE-2023-34058)

  • open-vm-tools: file descriptor hijack vulnerability in the vmware-user-suid-wrapper (CVE-2023-34059)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Затронутые продукты

  • Rocky Linux 8

НаименованиеАрхитектураРелизRPM
open-vm-toolsx86_643.el8_9.1open-vm-tools-12.2.5-3.el8_9.1.x86_64.rpm
open-vm-tools-desktopx86_643.el8_9.1open-vm-tools-desktop-12.2.5-3.el8_9.1.x86_64.rpm
open-vm-tools-salt-minionx86_643.el8_9.1open-vm-tools-salt-minion-12.2.5-3.el8_9.1.x86_64.rpm
open-vm-tools-sdmpx86_643.el8_9.1open-vm-tools-sdmp-12.2.5-3.el8_9.1.x86_64.rpm

Показывать по

Связанные CVE

Связанные уязвимости

suse-cvrf
больше 1 года назад

Security update for open-vm-tools

suse-cvrf
больше 1 года назад

Security update for open-vm-tools

suse-cvrf
больше 1 года назад

Security update for open-vm-tools

suse-cvrf
больше 1 года назад

Security update for open-vm-tools

oracle-oval
больше 1 года назад

ELSA-2023-7279: open-vm-tools security update (IMPORTANT)