It was discovered that Open VM Tools incorrectly handled SAML tokens. A remote attacker could possibly use this issue to bypass SAML token signature verification and perform VMware Tools Guest Operations.
{ "availability": "No subscription required", "binaries": [ { "binary_name": "open-vm-tools", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" }, { "binary_name": "open-vm-tools-dbgsym", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" }, { "binary_name": "open-vm-tools-desktop", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" }, { "binary_name": "open-vm-tools-desktop-dbgsym", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" }, { "binary_name": "open-vm-tools-dev", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" }, { "binary_name": "open-vm-tools-sdmp", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" }, { "binary_name": "open-vm-tools-sdmp-dbgsym", "binary_version": "2:11.3.0-2ubuntu0~ubuntu20.04.6" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "open-vm-tools", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-containerinfo", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-containerinfo-dbgsym", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-dbgsym", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-desktop", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-desktop-dbgsym", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-dev", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-salt-minion", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-sdmp", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" }, { "binary_name": "open-vm-tools-sdmp-dbgsym", "binary_version": "2:12.1.5-3~ubuntu0.22.04.3" } ] }