• [SECURITY] [DSA 5493-1] open-vm-tools security update

    From Moritz Muehlenhoff@21:1/5 to All on Sun Sep 10 20:00:01 2023
    -----BEGIN PGP SIGNED MESSAGE-----
    Hash: SHA512

    - ------------------------------------------------------------------------- Debian Security Advisory DSA-5493-1 security@debian.org https://www.debian.org/security/ Moritz Muehlenhoff September 10, 2023 https://www.debian.org/security/faq
    - -------------------------------------------------------------------------

    Package : open-vm-tools
    CVE ID : CVE-2023-20867 CVE-2023-20900
    Debian Bug : 1050970

    Two security issues have been discovered in the Open VMware Tools, which
    may result in a man-in-the-middle attack or authentication bypass.

    For the oldstable distribution (bullseye), these problems have been fixed
    in version 2:11.2.5-2+deb11u2.

    For the stable distribution (bookworm), these problems have been fixed in version 2:12.2.0-1+deb12u1.

    We recommend that you upgrade your open-vm-tools packages.

    For the detailed security status of open-vm-tools please refer to
    its security tracker page at: https://security-tracker.debian.org/tracker/open-vm-tools

    Further information about Debian Security Advisories, how to apply
    these updates to your system and frequently asked questions can be
    found at: https://www.debian.org/security/

    Mailing list: debian-security-announce@lists.debian.org
    -----BEGIN PGP SIGNATURE-----

    iQIzBAEBCgAdFiEEtuYvPRKsOElcDakFEMKTtsN8TjYFAmT+AygACgkQEMKTtsN8 TjbAdQ/+M8tP/Dv5EOKhkUxZPD2NzBajQdr4iBJa2ZEhnhL3plaon0YNlnKcbItv tS1S/u3Gp33TgJ6LfpRyQ18x2/5qloPcxVER5I5j4mkkHrdPKgzx+1dirRuz5oBJ 5FwQXWZoH3KJ6pGIc0EcNSrAEKgOqr0ISHAQ8LztXD3Oe6mtm6oxqmf24iYUmDwH MkAXihLOqETkz0Y0Cmn5QGUq7nUvV+at6zij+Su5fSyyyMo0WW9LZrGfNzL9t3QT rRl9VS/p8DRYIk6VBaF8foY1e7WfDXtiZXAVtAd53FFrSVPFlQWI9WETIDQqEGe6 m1isNBK+kCOKCKiceLRMvX+2qUy/KKJqyRYN/VZTMqxDDVZIuY6C0kJLaZ6P5png svwDF0PISIq77AM/S4bw5wKbIT8qNj8BCsrkRXeXFteoTtvygAr3rnWgv3nmLY9c XFXIBtDhs0TS/C4ZPAhZGqAf5AJ9AN636Wie5pmUxqjnf6ecGORKfiaT5GV0URjC 324IxAHh6ml0JcVKsUczxP7YjPlEP0LZ90tiUXYgLxQgBouTrBqOD1VdcNtZbvkz EYU3YDTCG7GNE3mod8COJV2ZdSAgi1V1by7j6gFDwSQrfkqUke5yLlYayQp90WPC oXGRR8ygOrTtRw70WQfVgWBqss0Ix1J0qnuIjrIZzhvkc8KGYeY=
    =+jTU
    -----END PGP SIGNATURE-----

    --- SoupGate-Win32 v1.05
    * Origin: fsxNet Usenet Gateway (21:1/5)