Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE: SU-2018:2295-1 Important: VirtualBox DoS Threat Report

opensuse
Calendar Grey August 10, 2018
Dist Opensuse Esm H88
A crucial update for Fedora addressing several VirtualBox vulnerabilities to improve overall system integrity and safeguard against potential threats.
An update that fixes 9 vulnerabilities is now available.

Description

This update for virtualbox to version 5.2.16 fixes the following issues:

The following security vulnerabilities were fixed (boo#1101667):

- CVE-2018-3005: Fixed an easily exploitable vulnerability that allowed

unauthenticated attacker with logon to the infrastructure where Oracle

VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful

attacks of this vulnerability can result in unauthorized ability to

cause a partial denial

of service (partial DOS) of Oracle VM VirtualBox.

- CVE-2018-3055: Fixed an easily exploitable vulnerability that allowed

unauthenticated attacker with logon to the infrastructure where Oracle

VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful

attacks require human interaction from a person other than the attacker

and while the vulnerability is in Oracle VM VirtualBox, attacks may

significantly impact additional products. Successful attacks of this

vulnerability...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-853=1

Package List

- openSUSE Leap 15.0 (x86_64):

python3-virtualbox-5.2.16-lp150.4.9.1

python3-virtualbox-debuginfo-5.2.16-lp150.4.9.1

virtualbox-5.2.16-lp150.4.9.1

virtualbox-debuginfo-5.2.16-lp150.4.9.1

virtualbox-debugsource-5.2.16-lp150.4.9.1

virtualbox-devel-5.2.16-lp150.4.9.1

virtualbox-guest-kmp-default-5.2.16_k4.12.14_lp150.12.7-lp150.4.9.1

virtualbox-guest-kmp-default-debuginfo-5.2.16_k4.12.14_lp150.12.7-lp150.4.9.1

virtualbox-guest-tools-5.2.16-lp150.4.9.1

virtualbox-guest-tools-debuginfo-5.2.16-lp150.4.9.1

virtualbox-guest-x11-5.2.16-lp150.4.9.1

virtualbox-guest-x11-debuginfo-5.2.16-lp150.4.9.1

virtualbox-host-kmp-default-5.2.16_k4.12.14_lp150.12.7-lp150.4.9.1

virtualbox-host-kmp-default-debuginfo-5.2.16_k4.12.14_lp150.12.7-lp150.4.9.1

virtualbox-qt-5.2.16-lp150.4.9.1

virtualbox-qt-debuginfo-5.2.16-lp150.4.9.1

virtualbox-vnc-5.2.16-lp150.4.9.1

virtualbox-websrv-5.2.16-lp150.4.9.1

virtualbox-websrv-debuginfo-5.2.16-lp150.4.9.1

- openSUSE Leap 15.0 (noarch):

virtualbox-guest-desktop-icons-5.2.16-lp150.4.9.1

virtualb...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-3005.html

https://www.suse.com/security/cve/CVE-2018-3055.html

https://www.suse.com/security/cve/CVE-2018-3085.html

https://www.suse.com/security/cve/CVE-2018-3086.html

https://www.suse.com/security/cve/CVE-2018-3087.html

https://www.suse.com/security/cve/CVE-2018-3088.html

https://www.suse.com/security/cve/CVE-2018-3089.html

https://www.suse.com/security/cve/CVE-2018-3090.html

https://www.suse.com/security/cve/CVE-2018-3091.html

https://bugzilla.suse.com/1101667

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:2295-1
Rating: important
Affected Products: openSUSE Leap 15.0

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here