Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 908555 (CVE-2023-20867) - <app-emulation/open-vm-tools-12.2.5: Possible denial of service vulnerability
Summary: <app-emulation/open-vm-tools-12.2.5: Possible denial of service vulnerability
Status: IN_PROGRESS
Alias: CVE-2023-20867
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: Normal minor (vote)
Assignee: Gentoo Security
URL: https://www.vmware.com/security/advis...
Whiteboard: B3 [glsa? cleanup]
Keywords:
Depends on: 908839
Blocks:
  Show dependency tree
 
Reported: 2023-06-15 23:49 UTC by Sam James
Modified: 2023-06-22 04:19 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-06-15 23:49:02 UTC
From https://github.com/vmware/open-vm-tools/releases/tag/stable-12.2.5

"""
Please refer to the release notes at https://github.com/vmware/open-vm-tools/blob/stable-12.2.5/ReleaseNotes.md

The granular changes that have gone into the 12.2.5 release are in the ChangeLog at https://github.com/vmware/open-vm-tools/blob/stable-12.2.5/open-vm-tools/ChangeLog

There are no new features in the open-vm-tools 12.2.5 release. This release resolves CVE-2023-20867. For more information on this vulnerability and its impact on VMware products, see https://www.vmware.com/security/advisories/VMSA-2023-0013.html.

For issues resolved in this release, see the Resolved Issues section of the Release Notes.
"""
Comment 1 Sam James archtester Gentoo Infrastructure gentoo-dev Security 2023-06-15 23:49:38 UTC
Please bump to 12.2.5.
Comment 2 Larry the Git Cow gentoo-dev 2023-06-18 20:25:06 UTC
The bug has been referenced in the following commit(s):

https://gitweb.gentoo.org/repo/gentoo.git/commit/?id=f214cddd9a728a547f8deccc652fa4c7a658bf0f

commit f214cddd9a728a547f8deccc652fa4c7a658bf0f
Author:     Mike Gilbert <floppym@gentoo.org>
AuthorDate: 2023-06-18 20:23:49 +0000
Commit:     Mike Gilbert <floppym@gentoo.org>
CommitDate: 2023-06-18 20:24:48 +0000

    app-emulation/open-vm-tools: add 12.2.5
    
    Bug: https://bugs.gentoo.org/908555
    Signed-off-by: Mike Gilbert <floppym@gentoo.org>

 app-emulation/open-vm-tools/Manifest               |   1 +
 .../open-vm-tools/open-vm-tools-12.2.5.ebuild      | 149 +++++++++++++++++++++
 2 files changed, 150 insertions(+)
Comment 3 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2023-06-19 03:14:09 UTC
Thanks! Please stable when ready.