Lucene search

K
centosCentOS ProjectCESA-2023:3944
HistoryJul 27, 2023 - 2:32 p.m.

open security update

2023-07-2714:32:46
CentOS Project
lists.centos.org
240
centos
cesa-2023:3944
open-vm-tools
vmware tools
authentication bypass
cve-2023-20867
esxi
rhel7
bz#1880404
bz#1994590

3.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

0.005 Low

EPSS

Percentile

76.6%

CentOS Errata and Security Advisory CESA-2023:3944

The Open Virtual Machine Tools are the open source implementation of the VMware Tools. They are a set of guest operating system virtualization components that enhance performance and user experience of virtual machines.

Security Fix(es):

  • open-vm-tools: authentication bypass vulnerability in the vgauth module (CVE-2023-20867)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • [ESXi] [RHEL7] vmtoolsd task is blocked in the uninterruptible state while attempting to delete (unlink) the file ‘quiesce_manifest.xml’ (BZ#1880404)

  • [ESXi][RHEL7.9][open-vm-tools] Snapshot of the RHEL7 guest on the VMWare ESXi hypervisor failed vm hangs (BZ#1994590)

Merged security bulletin from advisories:
https://lists.centos.org/pipermail/centos-announce/2023-July/086397.html

Affected packages:
open-vm-tools
open-vm-tools-desktop
open-vm-tools-devel
open-vm-tools-test

Upstream details at:
https://access.redhat.com/errata/RHSA-2023:3944

3.9 Low

CVSS3

Attack Vector

LOCAL

Attack Complexity

HIGH

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:L/I:L/A:N

0.005 Low

EPSS

Percentile

76.6%