GLSA Advocate
Joined: 12 May 2004 Posts: 2663
|
Posted: Sun Feb 11, 2018 11:26 pm Post subject: [ GLSA 201802-01 ] VirtualBox |
|
|
Gentoo Linux Security Advisory
Title: VirtualBox: Multiple vulnerabilities (GLSA 201802-01)
Severity: high
Exploitable: local, remote
Date: 2018-02-11
Bug(s): #644894
ID: 201802-01
Synopsis
Multiple vulnerabilities have been found in VirtualBox, the worst
of which could allow an attacker to take control of VirtualBox.
Background
VirtualBox is a powerful virtualization product from Oracle.
Affected Packages
Package: app-emulation/virtualbox
Vulnerable: < 5.1.32
Unaffected: >= 5.1.32
Architectures: All supported architectures
Package: app-emulation/virtualbox-bin
Vulnerable: < 5.1.32.120294
Unaffected: >= 5.1.32.120294
Architectures: All supported architectures
Package: app-emulation/virtualbox-guest-additions
Vulnerable: < 5.1.32
Unaffected: >= 5.1.32
Architectures: All supported architectures
Description
Multiple vulnerabilities have been discovered in VirtualBox. Please
review the CVE identifiers referenced below for details.
Impact
An attacker could take control of VirtualBox resulting in the execution
of arbitrary code with the privileges of the process, a Denial of Service
condition, or other unspecified impacts.
Workaround
There is no known workaround at this time.
Resolution
All VirtualBox users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose ">=app-emulation/virtualbox-5.1.32"
| All VirtualBox Binary users should upgrade to the latest version: Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=app-emulation/virtualbox-bin-5.1.32.120294"
| All VirtualBox Guest Additions users should upgrade to the latest
version:
Code: | # emerge --sync
# emerge --ask --oneshot --verbose
">=app-emulation/virtualbox-guest-additions-5.1.32"
|
References
CVE-2018-2676
CVE-2018-2685
CVE-2018-2686
CVE-2018-2687
CVE-2018-2688
CVE-2018-2689
CVE-2018-2690
CVE-2018-2693
CVE-2018-2694
CVE-2018-2698 |
|