Package: open-vm-tools / 2:11.2.5-2+deb11u3
Metadata
| Package | Version | Patches format |
|---|---|---|
| open-vm-tools | 2:11.2.5-2+deb11u3 | 3.0 (quilt) |
Patch series
view the series file| Patch | File delta | Description |
|---|---|---|
| use debian pam | (download) |
open-vm-tools/services/vmtoolsd/Makefile.am |
2 1 + 1 - 0 ! |
--- |
| debian/scsi udev rule | (download) |
open-vm-tools/udev/99-vmware-scsi-udev.rules |
4 2 + 2 - 0 ! |
--- |
| 1125 Properly check authorization on incoming guestOps re.patch | (download) |
open-vm-tools/vgauth/serviceImpl/proto.c |
6 5 + 1 - 0 ! |
[patch] properly check authorization on incoming guestops requests Fix public pipe request checks. Only a SessionRequest type should be accepted on the public pipe. |
| 2023 20867 Remove some dead code 1110 1125.patch | (download) |
open-vm-tools/services/plugins/vix/vixTools.c |
102 0 + 102 - 0 ! |
[patch] remove some dead code. Address CVE-2023-20867. Remove some authentication types which were deprecated long ago and are no longer in use. These are dead code. |
| CVE 2023 20900.patch | (download) |
open-vm-tools/vgauth/serviceImpl/saml-xmlsec1.c |
9 8 + 1 - 0 ! |
[patch] address cve-2023-20900 VGAuth: Allow only X509 certs to verify the SAML token signature. |
| CVE 2023 34059.patch | (download) |
open-vm-tools/services/vmtoolsd/mainPosix.c |
76 76 + 0 - 0 ! |
[patch] address cve-2023-34059 Fix file descriptor vulnerability in the open-vm-tools vmware-user-suid-wrapper on Linux. - Moving the privilege drop logic (dropping privilege to the real uid and gid of the process for the vmusr service) from suidWrapper to vmtoolsd code. |
| CVE 2023 34058.patch | (download) |
open-vm-tools/vgauth/common/certverify.c |
145 145 + 0 - 0 ! |
[patch] address cve-2023-34058 VGAuth: don't accept tokens with unrelated certs. |
