Bug#1018012: open-vm-tools: CVE-2022-31676: local privilege escalation

2022-08-24 Thread Salvatore Bonaccorso
Hi Bernd, On Wed, Aug 24, 2022 at 10:40:03AM +0200, Bernd Zeimetz wrote: > Hi security team, > > I've prepared uploads for bullseye and buster, diffs are attached. > CI is also happy: > https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/-/pipelines > > Is it okay to upload to

Bug#1018012: open-vm-tools: CVE-2022-31676: local privilege escalation

2022-08-24 Thread Bernd Zeimetz
Hi security team, I've prepared uploads for bullseye and buster, diffs are attached. CI is also happy: https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/-/pipelines Is it okay to upload to *-security? Thanks, Bernd On Wed, 2022-08-24 at 09:18 +0200, Salvatore Bonaccorso wrote:

Bug#1018012: open-vm-tools: CVE-2022-31676: local privilege escalation

2022-08-24 Thread Salvatore Bonaccorso
Source: open-vm-tools Version: 2:12.0.5-2 Severity: grave Tags: security upstream fixed-upstream Justification: user security hole X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for open-vm-tools. CVE-2022-31676[0]: | VMware Tools (12.0.0,