USN-6257-1: Open VM Tools vulnerability
It was discovered that Open VM Tools incorrectly handled certain authentication requests. A fully compromised ESXi host can force Open VM Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine. (CVE-2023-20867)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of USN-6257-1?
The vulnerability ID of USN-6257-1 is CVE-2023-20867.
What is the impact of CVE-2023-20867?
CVE-2023-20867 can allow a fully compromised ESXi host to force Open VM Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
How can I fix the Open VM Tools vulnerability in Ubuntu 23.04?
To fix the Open VM Tools vulnerability in Ubuntu 23.04, update the package to version 2:12.1.5-3ubuntu0.23.04.1.
How can I fix the Open VM Tools vulnerability in Ubuntu 22.04?
To fix the Open VM Tools vulnerability in Ubuntu 22.04, update the package to version 2:12.1.5-3~ubuntu0.22.04.2.
How can I fix the Open VM Tools vulnerability in Ubuntu 20.04?
To fix the Open VM Tools vulnerability in Ubuntu 20.04, update the package to version 2:11.3.0-2ubuntu0~ubuntu20.04.5.
How can I fix the Open VM Tools vulnerability in Ubuntu 18.04?
To fix the Open VM Tools vulnerability in Ubuntu 18.04, update the package to version 2:11.0.5-4ubuntu0.18.04.3+esm1.
How can I fix the Open VM Tools vulnerability in Ubuntu 16.04?
To fix the Open VM Tools vulnerability in Ubuntu 16.04, update the package to version 2:10.2.0-3~ubuntu0.16.04.1+esm2.