[ubuntu/noble-security] open-vm-tools 2:12.5.0-1~ubuntu0.24.04.2 (Accepted)
Hlib Korzhynskyy
hlib.korzhynskyy at canonical.com
Mon Sep 29 17:06:59 UTC 2025
open-vm-tools (2:12.5.0-1~ubuntu0.24.04.2) noble-security; urgency=medium
* SECURITY UPDATE: local privilege escalation in Service Discovery Plugin
- debian/patches/CVE-2025-41244.patch: disable by default the execution
of the SDMP get-versions.sh script in
open-vm-tools/services/plugins/serviceDiscovery/serviceDiscovery.c.
- CVE-2025-41244
open-vm-tools (2:12.5.0-1~ubuntu0.24.04.1) noble; urgency=medium
* Backport recent open-vm-tools release v12.5.0 (LP: #2122116)
- For changes included in this update, see:
https://github.com/vmware/open-vm-tools/blob/stable-12.5.0/ReleaseNotes.md
open-vm-tools (2:12.5.0-1ubuntu0.1) plucky-security; urgency=medium
* SECURITY UPDATE: insecure file handling vulnerability
- debian/patches/CVE-2025-22247.patch: properly check symlinks and path
traversal chars in open-vm-tools/vgauth/common/VGAuthUtil.c,
open-vm-tools/vgauth/common/VGAuthUtil.h,
open-vm-tools/vgauth/common/prefs.h,
open-vm-tools/vgauth/common/usercheck.c,
open-vm-tools/vgauth/serviceImpl/alias.c,
open-vm-tools/vgauth/serviceImpl/service.c,
open-vm-tools/vgauth/serviceImpl/serviceInt.h.
- CVE-2025-22247
open-vm-tools (2:12.5.0-1) unstable; urgency=medium
* Update to 12.5.0, full release notes can be found at
https://github.com/vmware/open-vm-tools/blob/stable-12.5.0/ReleaseNotes.md
- d/copyright: update to 12.5.0
- d/copyright: add missing path element to fix superfluous-file-pattern
- d/copyright: bsd files gone since 10.2.5
- d/*.lintian-overrides: fix paths
Date: 2025-09-23 17:26:24.106785+00:00
Changed-By: Marc Deslauriers <marc.deslauriers at canonical.com>
Signed-By: Hlib Korzhynskyy <hlib.korzhynskyy at canonical.com>
https://launchpad.net/ubuntu/+source/open-vm-tools/2:12.5.0-1~ubuntu0.24.04.2
-------------- next part --------------
Sorry, changesfile not available.
More information about the noble-changes
mailing list