[Git][security-tracker-team/security-tracker][master] open-vm-tools DSA

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 10 18:54:12 BST 2023



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
04ac0cad by Moritz Mühlenhoff at 2023-09-10T19:53:40+02:00
open-vm-tools DSA

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -56968,8 +56968,6 @@ CVE-2023-20868 (NSX-T contains a reflected cross-site scripting vulnerability du
 CVE-2023-20867 (A fully compromised ESXi host can force VMware Tools to fail to authen ...)
 	{DLA-3531-1}
 	- open-vm-tools 2:12.2.5-1 (bug #1037546)
-	[bookworm] - open-vm-tools <no-dsa> (Minor issue)
-	[bullseye] - open-vm-tools <no-dsa> (Minor issue)
 	NOTE: https://www.vmware.com/security/advisories/VMSA-2023-0013.html
 	NOTE: https://github.com/vmware/open-vm-tools/tree/CVE-2023-20867.patch
 CVE-2023-20866 (In Spring Session version 3.0.0, the session id can be logged to the s ...)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,7 @@
+[10 Sep 2023] DSA-5493-1 open-vm-tools - security update
+	{CVE-2023-20867 CVE-2023-20900}
+	[bullseye] - open-vm-tools 2:11.2.5-2+deb11u2
+	[bookworm] - open-vm-tools 2:12.2.0-1+deb12u1
 [09 Sep 2023] DSA-5492-1 linux - security update
 	{CVE-2023-1206 CVE-2023-1989 CVE-2023-2430 CVE-2023-2898 CVE-2023-3611 CVE-2023-3772 CVE-2023-3773 CVE-2023-3776 CVE-2023-3777 CVE-2023-3863 CVE-2023-4004 CVE-2023-4015 CVE-2023-4128 CVE-2023-4132 CVE-2023-4147 CVE-2023-4155 CVE-2023-4194 CVE-2023-4206 CVE-2023-4207 CVE-2023-4208 CVE-2023-4273 CVE-2023-4569 CVE-2023-4622 CVE-2023-20588 CVE-2023-34319 CVE-2023-40283}
 	[bookworm] - linux 6.1.52-1


=====================================
data/dsa-needed.txt
=====================================
@@ -38,8 +38,6 @@ nodejs
 --
 nova/oldstable
 --
-open-vm-tools (jmm)
---
 openjdk-17/oldstable (jmm)
 --
 php-cas/oldstable



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/04ac0cad02e300b994a2028f4238ce1fa57d46d0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/04ac0cad02e300b994a2028f4238ce1fa57d46d0
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20230910/82d4f61e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list