-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 1 Oct 2023 20:03:53 CEST Source: open-vm-tools Architecture: source Version: 2:10.3.10-1+deb10u5 Distribution: buster-security Urgency: high Maintainer: Bernd Zeimetz <bzed@debian.org> Changed-By: Markus Koschany <apo@debian.org> Checksums-Sha1: 3b1c72bf9af662f10d10799b5b74ad24e83a53fb 2509 open-vm-tools_10.3.10-1+deb10u5.dsc 3fe0f8e8877d502cd4c1e893d3075fbc88f3f6ca 48644 open-vm-tools_10.3.10-1+deb10u5.debian.tar.xz a5934dbb8d1b36f65793b9287957387a04760b18 17883 open-vm-tools_10.3.10-1+deb10u5_amd64.buildinfo Checksums-Sha256: b083bece0fb954d38ff7d3cda8c6bd7d34c0f5493c2c8774286c79cbaa3af6c9 2509 open-vm-tools_10.3.10-1+deb10u5.dsc 99d7c4cb5fc5b5eb65a72a5e5947fe8135be7cebd1abe8d53c6843d792737c6e 48644 open-vm-tools_10.3.10-1+deb10u5.debian.tar.xz 4643eec0d30f5ca42c6caccfdce0ddc2c10e0eb14592a9256b25840d05400c26 17883 open-vm-tools_10.3.10-1+deb10u5_amd64.buildinfo Closes: 1050970 Changes: open-vm-tools (2:10.3.10-1+deb10u5) buster-security; urgency=high . * Non-maintainer upload by the LTS team. * Allow only X509 certs to verify the SAML token signature (fixes: CVE-2023-20900) (Closes: #1050970). Files: c745afc3e9ee819989918743d51a7c2b 2509 admin extra open-vm-tools_10.3.10-1+deb10u5.dsc 63b0401a868df0543a43e289bbf396ba 48644 admin extra open-vm-tools_10.3.10-1+deb10u5.debian.tar.xz 5a6b034564eaaf09a2aa3e16fa5c8373 17883 admin extra open-vm-tools_10.3.10-1+deb10u5_amd64.buildinfo -----BEGIN PGP SIGNATURE----- iQKjBAEBCgCNFiEErPPQiO8y7e9qGoNf2a0UuVE7UeQFAmUZtSxfFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldEFD RjNEMDg4RUYzMkVERUY2QTFBODM1RkQ5QUQxNEI5NTEzQjUxRTQPHGFwb0BkZWJp YW4ub3JnAAoJENmtFLlRO1Hk1kEP/1IfwV8a6JJkNXAbzac1i3wCwveESrk8ZCO4 rUM+D2/U+m5Z0rINgupeGc48qVpX0wDsNztAbc1u8wxYOWrHoeqsD/Y2vDaugPdf z35d9Cum6d5FJhnFMKFxVov26O+eO6zKtpqBtzI7PWZTe0ug5CXQ0p1KQC3UnKdD +lq/pWwLzJTPVwHMxkTaAwTqj59T82sWhHmMGtgrM+lSaHm6m9AzNART10Wnutll +sBZCZgWv0dZpl+hmIww8aTUHidY1B26797im7P4yPJzz28mDUBDoxPfRLQ+ZN5p O7AlPVMElDOALZzG/7tCTbfNGLIO2cLZ7jhYWPCaJZ+L4wiCFF40Dc2cUgEeNlR/ 1rYx7WfPEZY8Up1R8rCcCQp4HnEm499VsAOObwHg/gNCBF1VGgnIraQkD5URx/nW 7OhnA6dqrGccy8tI52uSbrkqjkrEugd7nP9+peaCdFON3kDxdYP0MGpfOaRduj++ GR+OFzlpEeaGI7oDU4q8CgmytHU9D9jg9inGTlcNKD1novPW3EaDDbxQBl+VfZsO ZEhaNEYRn5KxO28lmzAlND3v1FAAjfAUfuufu4uEi+1M4ZXdxP8Rx0XxT9xYiJME NBTigXHSvK7Od4Fhh0YYiwgu19En0G2QP0IagzobkgA8hg0UIPnX9imO4MbJTNxE kw+N3oOb =8xYO -----END PGP SIGNATURE-----