Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:0187-1

Опубликовано: 23 янв. 2018
Источник: suse-cvrf

Описание

Security update for virtualbox

This update for virtualbox to version 5.1.32 fixes the following issues:

The following vulnerabilities were fixed (boo#1076372):

  • CVE-2017-5715: Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, also known as 'Spectre', bsc#1068032.
  • CVE-2018-2676: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2685: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2686: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2687: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2688: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2689: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2690: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2693: Local authenticated attacker may gain elevated privileges via guest additions
  • CVE-2018-2694: Local authenticated attacker may gain elevated privileges
  • CVE-2018-2698: Local authenticated attacker may gain elevated privileges

The following bug fixes are included:

  • fix occasional screen corruption when host screen resolution is changed
  • increase proposed disk size when creating new VMs for Windows 7 and newer
  • fix broken communication with certain devices on Linux hosts
  • Fix problems using 256MB VRAM in raw-mode VMs
  • add HDA support for more exotic guests (e.g. Haiku)
  • fix playback with ALSA backend (5.1.28 regression)
  • fix a problem where OHCI emulation might sporadically drop data transfers

Список пакетов

openSUSE Leap 42.2
python-virtualbox-5.1.32-42.1
virtualbox-5.1.32-42.1
virtualbox-devel-5.1.32-42.1
virtualbox-guest-desktop-icons-5.1.32-42.1
virtualbox-guest-kmp-default-5.1.32_k4.4.104_39-42.1
virtualbox-guest-source-5.1.32-42.1
virtualbox-guest-tools-5.1.32-42.1
virtualbox-guest-x11-5.1.32-42.1
virtualbox-host-kmp-default-5.1.32_k4.4.104_39-42.1
virtualbox-host-source-5.1.32-42.1
virtualbox-qt-5.1.32-42.1
virtualbox-vnc-5.1.32-42.1
virtualbox-websrv-5.1.32-42.1
openSUSE Leap 42.3
python-virtualbox-5.1.32-42.1
virtualbox-5.1.32-42.1
virtualbox-devel-5.1.32-42.1
virtualbox-guest-desktop-icons-5.1.32-42.1
virtualbox-guest-kmp-default-5.1.32_k4.4.104_39-42.1
virtualbox-guest-source-5.1.32-42.1
virtualbox-guest-tools-5.1.32-42.1
virtualbox-guest-x11-5.1.32-42.1
virtualbox-host-kmp-default-5.1.32_k4.4.104_39-42.1
virtualbox-host-source-5.1.32-42.1
virtualbox-qt-5.1.32-42.1
virtualbox-vnc-5.1.32-42.1
virtualbox-websrv-5.1.32-42.1

Описание

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Guest Additions). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.2:python-virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-devel-5.1.32-42.1
openSUSE Leap 42.2:virtualbox-guest-desktop-icons-5.1.32-42.1

Ссылки
Уязвимость openSUSE-SU-2018:0187-1