CVE-2023-34059
Summary
| CVE | CVE-2023-34059 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-10-27 05:15:00 UTC |
| Updated | 2023-11-08 04:15:00 UTC |
| Description | open-vm-tools contains a file descriptor hijack vulnerability in the vmware-user-suid-wrapper. A malicious actor with non-root privileges may be able to hijack the /dev/uinput file descriptor allowing them to simulate user inputs. |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 10.0 | All | All | All |
| Operating System | Debian | Debian Linux | 11.0 | All | All | All |
| Operating System | Debian | Debian Linux | 12.0 | All | All | All |
| Application | Vmware | Open Vm Tools | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| VMSA-2023-0024 | MISC | www.vmware.com | |
| oss-security - CVE-2023-34059 - File Descriptor Hijack vulnerability in open-vm-tools | MISC | www.openwall.com | |
| [SECURITY] Fedora 39 Update: open-vm-tools-12.3.0-3.fc39 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] Fedora 38 Update: open-vm-tools-12.3.0-3.fc38 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| Debian -- Security Information -- DSA-5543-1 open-vm-tools | MISC | www.debian.org | |
| oss-security - Re: CVE-2023-34059 - File Descriptor Hijack vulnerability in open-vm-tools | MISC | www.openwall.com | |
| [SECURITY] Fedora 37 Update: open-vm-tools-12.3.0-3.fc37 - package-announce - Fedora Mailing-Lists | lists.fedoraproject.org | ||
| [SECURITY] [DLA 3646-1] open-vm-tools security update | MISC | lists.debian.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 161132 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2023-7279)
- 161133 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2023-7277)
- 161157 Oracle Enterprise Linux Security Update for open-vm-tools (ELSA-2023-7265)
- 199880 Ubuntu Security Notification for Open VM Tools Vulnerabilities (USN-6463-1)
- 199985 Ubuntu Security Notification for Open VM Tools Vulnerability (USN-6463-2)
- 242467 Red Hat Update for open-vm-tools (RHSA-2023:7279)
- 242471 Red Hat Update for open-vm-tools (RHSA-2023:7265)
- 242472 Red Hat Update for open-vm-tools (RHSA-2023:7277)
- 242473 Red Hat Update for open-vm-tools (RHSA-2023:7264)
- 242474 Red Hat Update for open-vm-tools (RHSA-2023:7276)
- 242475 Red Hat Update for open-vm-tools (RHSA-2023:7267)
- 242596 Red Hat Update for open-vm-tools (RHSA-2023:7262)
- 242601 Red Hat Update for open-vm-tools (RHSA-2023:7263)
- 242608 Red Hat Update for open-vm-tools (RHSA-2023:7260)
- 242619 Red Hat Update for open-vm-tools (RHSA-2023:7261)
- 257282 CentOS Security Update for open-vm-tools (CESA-2023:7279)
- 284713 Fedora Security Update for open (FEDORA-2023-1ed0ec0035)
- 284714 Fedora Security Update for open (FEDORA-2023-08e2bb6815)
- 285163 Fedora Security Update for open (FEDORA-2023-86a50ffc72)
- 356608 Amazon Linux Security Advisory for open-vm-tools : ALAS2-2023-2329
- 356636 Amazon Linux Security Advisory for open-vm-tools : ALAS2023-2023-423
- 379041 Alibaba Cloud Linux Security Update for open-vm-tools (ALINUX2-SA-2023:0048)
- 379196 Alibaba Cloud Linux Security Update for open-vm-tools (ALINUX3-SA-2023:0140)
- 6000262 Debian Security Update for open-vm-tools (DLA 3646-1)
- 6000314 Debian Security Update for open-vm-tools (DSA 5543-1)
- 6140274 AWS Bottlerocket Security Update for open-vm-tools (GHSA-5mj7-55gx-r3qf)
- 691343 Free Berkeley Software Distribution (FreeBSD) Security Update for open (d2505ec7-78ea-11ee-9131-6f01853956d5)
- 755172 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2023:4230-1)
- 755173 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2023:4229-1)
- 755174 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2023:4228-1)
- 755175 SUSE Enterprise Linux Security Update for open-vm-tools (SUSE-SU-2023:4227-1)
- 941417 AlmaLinux Security Update for open-vm-tools (ALSA-2023:7277)
- 941477 AlmaLinux Security Update for open-vm-tools (ALSA-2023:7265)
- 961081 Rocky Linux Security Update for open-vm-tools (RLSA-2023:7265)