UbuntuUpdates.org

Package "open-vm-tools"

Name: open-vm-tools

Description:

Open VMware Tools for virtual machines hosted on VMware (CLI)

Latest version: 2:12.3.5-3~ubuntu0.23.10.1
Release: mantic (23.10)
Level: updates
Repository: main
Homepage: https://github.com/vmware/open-vm-tools

Links


Download "open-vm-tools"


Other versions of "open-vm-tools" in Mantic

Repository Area Version
base universe 2:12.3.0-1
base main 2:12.3.0-1
security main 2:12.3.0-1ubuntu0.1
security universe 2:12.3.0-1ubuntu0.1
updates universe 2:12.3.5-3~ubuntu0.23.10.1
PPA: Mint Upstream 2:11.3.5-1ubuntu5mint1

Packages in group

Deleted packages are displayed in grey.


Changelog

Version: 2:12.3.5-3~ubuntu0.23.10.1 2024-02-08 20:06:57 UTC

  open-vm-tools (2:12.3.5-3~ubuntu0.23.10.1) mantic; urgency=medium

  * Backport recent open-vm-tools release v12.3.5
    (LP: #2028420)

Source diff to previous version
2028420 Backport open-vm-tools 12.3.5 for jammy, lunar and mantic

Version: 2:12.3.0-1ubuntu0.1 2023-10-31 17:13:51 UTC

  open-vm-tools (2:12.3.0-1ubuntu0.1) mantic-security; urgency=medium

  * SECURITY UPDATE: SAML Bypass
    - debian/patches/CVE-2023-34058.patch: don't accept tokens with
      unrelated certs in open-vm-tools/vgauth/common/certverify.c,
      open-vm-tools/vgauth/common/certverify.h,
      open-vm-tools/vgauth/common/prefs.h,
      open-vm-tools/vgauth/serviceImpl/saml-xmlsec1.c.
    - CVE-2023-34058
  * SECURITY UPDATE: file descriptor hijack
    - debian/patches/CVE-2023-34059.patch: change privilege dropping order
      in open-vm-tools/services/vmtoolsd/mainPosix.c,
      open-vm-tools/vmware-user-suid-wrapper/main.c.
    - CVE-2023-34059

 -- Marc Deslauriers <email address hidden> Fri, 27 Oct 2023 07:24:07 -0400

CVE-2023-34058 VMware Tools contains a SAML token signature bypass vulnerability. A malicious actor that has been granted Guest Operation Privileges https://docs.v



About   -   Send Feedback to @ubuntu_updates