First published: Mon Sep 25 2023(Updated: )
USN-6365-1 fixed a vulnerability in Open VM Tools. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker could possibly use this issue to bypass SAML token signature verification and perform VMware Tools Guest Operations.
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/open-vm-tools | <2:11.0.5-4ubuntu0.18.04.3+esm2 | 2:11.0.5-4ubuntu0.18.04.3+esm2 |
=18.04 | ||
All of | ||
ubuntu/open-vm-tools | <2:10.2.0-3~ubuntu0.16.04.1+esm3 | 2:10.2.0-3~ubuntu0.16.04.1+esm3 |
=16.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Open VM Tools vulnerability is USN-6365-2.
The affected software for this vulnerability is Open VM Tools version 2:11.0.5-4ubuntu0.18.04.3+esm2 on Ubuntu 18.04 LTS and version 2:10.2.0-3~ubuntu0.16.04.1+esm3 on Ubuntu 16.04 LTS.
The severity of this vulnerability is not specified.
To fix this vulnerability, update Open VM Tools to the specified versions: 2:11.0.5-4ubuntu0.18.04.3+esm2 on Ubuntu 18.04 LTS and 2:10.2.0-3~ubuntu0.16.04.1+esm3 on Ubuntu 16.04 LTS.
You can find more information about this vulnerability on the Ubuntu website at the following URLs: - [CVE-2023-20900](https://ubuntu.com/security/CVE-2023-20900) - [USN-6365-1](https://ubuntu.com/security/notices/USN-6365-1) - [USN-6365-2](https://ubuntu.com/security/notices/USN-6365-2)