Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-07 Thread Bernd Zeimetz
> Hi, > > https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/-/compare/15b2b38edd7834b7ad93ae25831fc7ef2bf7ce28...bullseye?from_project_id=38835=false > > > > bookworm: > >

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-07 Thread Moritz Muehlenhoff
On Thu, Sep 07, 2023 at 11:43:27AM +0200, Bernd Zeimetz wrote: > Hi Moritz, > > > Ack, that's perfectly fine! > > > > Thanks! > > Here are the current diffs: > > bullseye: >

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-07 Thread Bernd Zeimetz
Hi Moritz, Ack, that's perfectly fine! Thanks! Here are the current diffs: bullseye: https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/-/compare/15b2b38edd7834b7ad93ae25831fc7ef2bf7ce28...bullseye?from_project_id=38835=false bookworm:

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-06 Thread Moritz Muehlenhoff
On Wed, Sep 06, 2023 at 08:11:17PM +0200, Bernd Zeimetz wrote: > Hi security team, > > I'm preparing security uploads for bookworm-security and buster-security > for > > > CVE-2023-20900[0]: > > | VMware Tools contains a SAML token signature bypass vulnerability. A > > | malicious actor with

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-06 Thread Bernd Zeimetz
On 2023-09-06 20:11, Bernd Zeimetz wrote: Hi security team, I'm preparing security uploads for bookworm-security and buster-security (bullseye-security of course... - we clearly have too many relases with bu) -- Bernd ZeimetzDebian GNU/Linux Developer

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-09-06 Thread Bernd Zeimetz
Hi security team, I'm preparing security uploads for bookworm-security and buster-security for CVE-2023-20900[0]: | VMware Tools contains a SAML token signature bypass vulnerability. A | malicious actor with man-in-the-middle (MITM) network positioning | between vCenter server and the virtual

Bug#1050970: open-vm-tools: CVE-2023-20900

2023-08-31 Thread Salvatore Bonaccorso
Source: open-vm-tools Version: 2:12.2.5-1 Severity: important Tags: security upstream X-Debbugs-Cc: car...@debian.org, Debian Security Team Hi, The following vulnerability was published for open-vm-tools. CVE-2023-20900[0]: | VMware Tools contains a SAML token signature bypass vulnerability. A