USN-6365-2: Open VM Tools vulnerability
USN-6365-1 fixed a vulnerability in Open VM Tools. This update provides the corresponding update for Ubuntu 16.04 LTS and Ubuntu 18.04 LTS. Original advisory details: It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker could possibly use this issue to bypass SAML token signature verification and perform VMware Tools Guest Operations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Open VM Tools vulnerability?
The vulnerability ID for this Open VM Tools vulnerability is USN-6365-2.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Open VM Tools version 2:11.0.5-4ubuntu0.18.04.3+esm2 on Ubuntu 18.04 LTS and version 2:10.2.0-3~ubuntu0.16.04.1+esm3 on Ubuntu 16.04 LTS.
What is the severity of this vulnerability?
The severity of this vulnerability is not specified.
How can I fix this vulnerability?
To fix this vulnerability, update Open VM Tools to the specified versions: 2:11.0.5-4ubuntu0.18.04.3+esm2 on Ubuntu 18.04 LTS and 2:10.2.0-3~ubuntu0.16.04.1+esm3 on Ubuntu 16.04 LTS.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Ubuntu website at the following URLs: - [CVE-2023-20900](https://ubuntu.com/security/CVE-2023-20900) - [USN-6365-1](https://ubuntu.com/security/notices/USN-6365-1) - [USN-6365-2](https://ubuntu.com/security/notices/USN-6365-2)