First published: Wed Oct 25 2023(Updated: )
open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs.
Credit: security@vmware.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/open-vm-tools | <2:11.0.5-4ubuntu0.18.04.3+ | 2:11.0.5-4ubuntu0.18.04.3+ |
ubuntu/open-vm-tools | <2:11.3.0-2ubuntu0~ubuntu20.04.7 | 2:11.3.0-2ubuntu0~ubuntu20.04.7 |
ubuntu/open-vm-tools | <2:12.1.5-3~ubuntu0.22.04.4 | 2:12.1.5-3~ubuntu0.22.04.4 |
ubuntu/open-vm-tools | <2:12.1.5-3ubuntu0.23.04.3 | 2:12.1.5-3ubuntu0.23.04.3 |
ubuntu/open-vm-tools | <2:12.3.0-1ubuntu0.1 | 2:12.3.0-1ubuntu0.1 |
ubuntu/open-vm-tools | <2:10.2.0-3~ubuntu0.16.04.1+ | 2:10.2.0-3~ubuntu0.16.04.1+ |
redhat/open-vm-tools | <11.0.0 | 11.0.0 |
debian/open-vm-tools | 2:11.2.5-2+deb11u3 2:12.2.0-1+deb12u2 2:12.4.5-1 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
IBM InfoSphere Guardium z/OS | <=11.4 | |
IBM InfoSphere Guardium z/OS | <=11.5 | |
IBM InfoSphere Guardium z/OS | <=12.0 | |
Red Hat Open VM Tools Desktop | >=11.0.0<=12.3.0 | |
Debian Linux | =10.0 | |
Debian Linux | =11.0 | |
Debian Linux | =12.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34059 has a medium severity rating due to its potential to allow non-root users to hijack file descriptors.
To mitigate CVE-2023-34059, update open-vm-tools to the latest version available for your Linux distribution.
CVE-2023-34059 affects multiple versions of open-vm-tools below 2:12.3.0 and can vary across different Linux distributions.
The vendor of the affected software in CVE-2023-34059 is VMware.
CVE-2023-34059 is a file descriptor hijack vulnerability in the vmware-user-suid-wrapper.