First published: Tue Oct 31 2023(Updated: )
It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker Guest Operations privileges could possibly use this issue to escalate privileges. (CVE-2023-34058) Matthias Gerstner discovered that Open VM Tools incorrectly handled file descriptors when dropping privileges. A local attacker could possibly use this issue to hijack /dev/uinput and simulate user inputs. (CVE-2023-34059)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/open-vm-tools | <2:12.3.0-1ubuntu0.1 | 2:12.3.0-1ubuntu0.1 |
Ubuntu Linux | =23.10 | |
All of | ||
ubuntu/open-vm-tools-desktop | <2:12.3.0-1ubuntu0.1 | 2:12.3.0-1ubuntu0.1 |
Ubuntu Linux | =23.10 | |
All of | ||
ubuntu/open-vm-tools | <2:12.1.5-3ubuntu0.23.04.3 | 2:12.1.5-3ubuntu0.23.04.3 |
Ubuntu Linux | =23.04 | |
All of | ||
ubuntu/open-vm-tools-desktop | <2:12.1.5-3ubuntu0.23.04.3 | 2:12.1.5-3ubuntu0.23.04.3 |
Ubuntu Linux | =23.04 | |
All of | ||
ubuntu/open-vm-tools | <2:12.1.5-3~ubuntu0.22.04.4 | 2:12.1.5-3~ubuntu0.22.04.4 |
Ubuntu Linux | =22.04 | |
All of | ||
ubuntu/open-vm-tools-desktop | <2:12.1.5-3~ubuntu0.22.04.4 | 2:12.1.5-3~ubuntu0.22.04.4 |
Ubuntu Linux | =22.04 | |
All of | ||
ubuntu/open-vm-tools | <2:11.3.0-2ubuntu0~ubuntu20.04.7 | 2:11.3.0-2ubuntu0~ubuntu20.04.7 |
Ubuntu Linux | =20.04 | |
All of | ||
ubuntu/open-vm-tools-desktop | <2:11.3.0-2ubuntu0~ubuntu20.04.7 | 2:11.3.0-2ubuntu0~ubuntu20.04.7 |
Ubuntu Linux | =20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-34058
Open VM Tools
A remote attacker with Guest Operations privileges could possibly use this issue to escalate privileges.
Update to version 2:12.3.0-1ubuntu0.1 of open-vm-tools package.
You can find more information about the vulnerability at the following references: CVE-2023-34059, CVE-2023-34058, and the Ubuntu security advisory.