Summary: | <app-emulation/open-vm-tools-12.3.5: multiple vulnerabilities | ||
---|---|---|---|
Product: | Gentoo Security | Reporter: | John Helmert III <ajak> |
Component: | Vulnerabilities | Assignee: | Gentoo Security <security> |
Status: | IN_PROGRESS --- | ||
Severity: | normal | CC: | ajak, maintainer-needed |
Priority: | Normal | ||
Version: | unspecified | ||
Hardware: | All | ||
OS: | Linux | ||
Whiteboard: | B2 [glsa?] | ||
Package list: | Runtime testing required: | --- |
Description
John Helmert III
2023-11-24 16:46:58 UTC
CVE-2023-20900 is fixed in 12.3.0 and 12.3.5, patch is in as 74b6d0d9000eda1a2c8f31c40c725fb0b8520b16. CVE-2023-34058 seems to be fixed in 1bfe23d728b74e08f4f65cd9b0093ca73937003a, which is in 12.3.5. CVE-2023-34059 seemingly has its patch in 12.3.5 too: https://github.com/vmware/open-vm-tools/commit/63f7c79c4aecb14d37cc4ce9da509419e31d394f Asking for more info from Matthias on oss-security. Yes, it seems I misunderstood him and that these are fixed. |