Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-31 Thread Moritz Muehlenhoff
On Tue, Oct 31, 2023 at 10:29:55AM +0100, Bernd Zeimetz wrote: > > Both uploaded! DSA has been released, thanks! Cheers, Moritz

Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-31 Thread Bernd Zeimetz
On Mon, 2023-10-30 at 22:50 +0100, Moritz Muehlenhoff wrote: > On Mon, Oct 30, 2023 at 07:09:53PM +0100, Bernd Zeimetz wrote: > > Hi Moritz, > > > > as usual, stable/oldstable updates prepared, diffs are attached to > > this > > mail as salsa seems to have some issues right now. > > > >

Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-30 Thread Moritz Muehlenhoff
On Mon, Oct 30, 2023 at 07:09:53PM +0100, Bernd Zeimetz wrote: > Hi Moritz, > > as usual, stable/oldstable updates prepared, diffs are attached to this > mail as salsa seems to have some issues right now. > > https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/ - > bookworm/bullseye

Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-30 Thread Bernd Zeimetz
Hi Moritz, as usual, stable/oldstable updates prepared, diffs are attached to this mail as salsa seems to have some issues right now. https://salsa.debian.org/vmware-packaging-team/pkg-open-vm-tools/ - bookworm/bullseye branches are actually there. Please let me know if/when I can upload.

Bug#1054666: open-vm-tools: CVE-2023-34059 CVE-2023-34058

2023-10-27 Thread Moritz Mühlenhoff
Source: open-vm-tools X-Debbugs-CC: t...@security.debian.org Severity: grave Tags: security Hi, The following vulnerabilities were published for open-vm-tools. CVE-2023-34059[0]: | open-vm-tools contains a file descriptor hijack vulnerability in the | vmware-user-suid-wrapper. A malicious actor