Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Mageia 8: 2023-0024 Critical Advisory for VirtualBox Compromise

mageia
Calendar Grey January 24, 2023
Dist Mageia Esm H88
Recent updates to VirtualBox have rectified security vulnerabilities in Mageia, enhancing the safety of infrastructure connections. Find out more here.
Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox

Summary

Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. (CVE-2023-21884)
Unauthenticated attacker with network access via multiple protocols to compromise Oracle VM VirtualBox.(CVE-2023-21886)
Low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox (CVE-2023-21889)
For other changes see referenced changelog.

References

- https://bugs.mageia.org/show_bug.cgi?id=31429

- https://www.oracle.com/security-alerts/cpujan2023.html#AppendixOVIR

-

- https://www.cve.org/CVERecord?id=CVE-2023-21884

- https://www.cve.org/CVERecord?id=CVE-2023-21886

- https://www.cve.org/CVERecord?id=CVE-2023-21889

Resolution

SRPMS

- 8/core/virtualbox-7.0.6-1.mga8

- 8/core/kmod-virtualbox-7.0.6-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 24 Jan 2023
URL: https://advisories.mageia.org/MGASA-2023-0024.html
Type: security
CVE: CVE-2023-21884, CVE-2023-21886, CVE-2023-21889

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here