Описание
Security update for open-vm-tools
This update for open-vm-tools fixes the following issues:
- CVE-2023-20900: Fixed SAML token signature bypass vulnerability (bsc#1214566).
This update also ships a open-vm-tools-containerinfo plugin. (jsc#PED-3421)
Список пакетов
Container suse/sle-micro-rancher/5.2:latest
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
Container suse/sle-micro-rancher/5.3:latest
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
Container suse/sle-micro-rancher/5.4:latest
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
Container suse/sle-micro/5.5:latest
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
Image SLES15-SP3-CHOST-BYOS-SAP-CCloud
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
Image SLES15-SP4-CHOST-BYOS-SAP-CCloud
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
Image SLES15-SP5-CHOST-BYOS-SAP-CCloud
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
SUSE Enterprise Storage 7.1
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Linux Enterprise High Performance Computing 15 SP3-ESPOS
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Linux Enterprise High Performance Computing 15 SP3-LTSS
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Linux Enterprise Micro 5.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
SUSE Linux Enterprise Micro 5.2
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
SUSE Linux Enterprise Micro 5.3
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
SUSE Linux Enterprise Micro 5.4
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
SUSE Linux Enterprise Module for Basesystem 15 SP4
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Linux Enterprise Module for Basesystem 15 SP5
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP4
open-vm-tools-desktop-12.2.0-150300.33.1
SUSE Linux Enterprise Module for Desktop Applications 15 SP5
open-vm-tools-desktop-12.2.0-150300.33.1
SUSE Linux Enterprise Server 15 SP3-LTSS
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Linux Enterprise Server for SAP Applications 15 SP3
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Manager Proxy 4.2
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
SUSE Manager Server 4.2
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
openSUSE Leap 15.4
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
openSUSE Leap 15.5
libvmtools-devel-12.2.0-150300.33.1
libvmtools0-12.2.0-150300.33.1
open-vm-tools-12.2.0-150300.33.1
open-vm-tools-containerinfo-12.2.0-150300.33.1
open-vm-tools-desktop-12.2.0-150300.33.1
open-vm-tools-salt-minion-12.2.0-150300.33.1
open-vm-tools-sdmp-12.2.0-150300.33.1
Ссылки
- Link for SUSE-SU-2023:3507-1
- E-Mail link for SUSE-SU-2023:3507-1
- SUSE Security Ratings
- SUSE Bug 1214566
- SUSE CVE CVE-2023-20900 page
Описание
A malicious actor that has been granted Guest Operation Privileges https://docs.vmware.com/en/VMware-vSphere/8.0/vsphere-security/GUID-6A952214-0E5E-4CCF-9D2A-90948FF643EC.html in a target virtual machine may be able to elevate their privileges if that target virtual machine has been assigned a more privileged Guest Alias https://vdc-download.vmware.com/vmwb-repository/dcr-public/d1902b0e-d479-46bf-8ac9-cee0e31e8ec0/07ce8dbd-db48-4261-9b8f-c6d3ad8ba472/vim.vm.guest.AliasManager.html .
Затронутые продукты
Container suse/sle-micro-rancher/5.2:latest:libvmtools0-12.2.0-150300.33.1
Container suse/sle-micro-rancher/5.2:latest:open-vm-tools-12.2.0-150300.33.1
Container suse/sle-micro-rancher/5.3:latest:libvmtools0-12.2.0-150300.33.1
Container suse/sle-micro-rancher/5.3:latest:open-vm-tools-12.2.0-150300.33.1
Ссылки
- CVE-2023-20900
- SUSE Bug 1214566
- SUSE Bug 1216432
- SUSE Bug 1216433
- SUSE Bug 1225628
- SUSE Bug 1228309