Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2018:2524-1

Опубликовано: 26 авг. 2018
Источник: suse-cvrf

Описание

Security update for kbuild, virtualbox

This update for kbuild, virtualbox fixes the following issues:

kbuild changes:

  • Update to version 0.1.9998svn3110
  • Do not assume glibc glob internals
  • Support GLIBC glob interface version 2
  • Fix build failure (boo#1079838)
  • Fix build with GCC7 (boo#1039375)
  • Fix build by disabling vboxvideo_drv.so

virtualbox security fixes (boo#1101667, boo#1076372):

  • CVE-2018-3005
  • CVE-2018-3055
  • CVE-2018-3085
  • CVE-2018-3086
  • CVE-2018-3087
  • CVE-2018-3088
  • CVE-2018-3089
  • CVE-2018-3090
  • CVE-2018-3091
  • CVE-2018-2694
  • CVE-2018-2698
  • CVE-2018-2685
  • CVE-2018-2686
  • CVE-2018-2687
  • CVE-2018-2688
  • CVE-2018-2689
  • CVE-2018-2690
  • CVE-2018-2676
  • CVE-2018-2693
  • CVE-2017-5715

virtualbox other changes:

  • Version bump to 5.2.16
  • Use %{?linux_make_arch} when building kernel modules (boo#1098050)
  • Fixed vboxguestconfig.sh script
  • Update warning regarding the security hole in USB passthrough. (boo#1097248)
  • Fixed include for build with Qt 5.11 (boo#1093731)
  • You can find a detailed list of changes here

Список пакетов

openSUSE Leap 42.3
kbuild-0.1.9998svn3110-4.3.1
python-virtualbox-5.2.18-56.1
virtualbox-5.2.18-56.1
virtualbox-devel-5.2.18-56.1
virtualbox-guest-desktop-icons-5.2.18-56.1
virtualbox-guest-kmp-default-5.2.18_k4.4.143_65-56.1
virtualbox-guest-source-5.2.18-56.1
virtualbox-guest-tools-5.2.18-56.1
virtualbox-guest-x11-5.2.18-56.1
virtualbox-host-kmp-default-5.2.18_k4.4.143_65-56.1
virtualbox-host-source-5.2.18-56.1
virtualbox-qt-5.2.18-56.1
virtualbox-vnc-5.2.18-56.1
virtualbox-websrv-5.2.18-56.1

Описание

Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Constructed ASN.1 types with a recursive definition (such as can be found in PKCS7) could eventually exceed the stack given malicious input with excessive recursion. This could result in a Denial Of Service attack. There are no such structures used within SSL/TLS that come from untrusted sources so this is considered safe. Fixed in OpenSSL 1.1.0h (Affected 1.1.0-1.1.0g). Fixed in OpenSSL 1.0.2o (Affected 1.0.2b-1.0.2n).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Guest Additions). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 3.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox as well as unauthorized update, insert or delete access to some of Oracle VM VirtualBox accessible data and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.36 and Prior to 5.2.10. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 4.0 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 7.1 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:N/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle VM VirtualBox accessible data as well as unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:L/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки

Описание

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.2.16. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data. CVSS 3.0 Base Score 6.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N).


Затронутые продукты
openSUSE Leap 42.3:kbuild-0.1.9998svn3110-4.3.1
openSUSE Leap 42.3:python-virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-5.2.18-56.1
openSUSE Leap 42.3:virtualbox-devel-5.2.18-56.1

Ссылки
Уязвимость openSUSE-SU-2018:2524-1