OpenSSL versions 1.1.0 through 1.1.0j and 1.1.1 through 1.1.1b are susceptible to a vulnerability that could lead to disclosure of sensitive information or the addition or modification of data (CVE-2019-1543). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability . MGASA-2019-0216 - Updated virtualbox packages fix security vulnerabilities Publication date: 27 Jul 2019 URL: https://advisories.mageia.org/MGASA-2019-0216.html Type: security Affected Mageia releases: 6, 7 CVE: CVE-2019-1543, CVE-2019-2848, CVE-2019-2850, CVE-2019-2859, CVE-2019-2863, CVE-2019-2864, CVE-2019-2865, CVE-2019-2866, CVE-2019-2867, CVE-2019-2873, CVE-2019-2874, CVE-2019-2875, CVE-2019-2876, CVE-2019-2877 OpenSSL versions 1.1.0 through 1.1.0j and 1.1.1 through 1.1.1b are susceptible to a vulnerability that could lead to disclosure of sensitive information or the addition or modification of data (CVE-2019-1543). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability that allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox (CVE-2019-2848). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability that allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox (CVE-2019-2850). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability thatallows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2019-2859). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability that allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data (CVE-2019-2863). Oracle VM VirtualBox prior to 6.0.10 has a difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2019-2864, CVE-2019-2865). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2019-2866, CVE-2019-2867). Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability that allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denialof service (partial DOS) of Oracle VM VirtualBox (CVE-2019-2873, CVE-2019-2874, CVE-2019-2875, CVE-2019-2876, CVE-2019-2877). References: - https://bugs.mageia.org/show_bug.cgi?id=25161 - https://www.oracle.com/security-alerts/cpujul2019.html - https://www.cve.org/CVERecord?id=CVE-2019-1543 - https://www.cve.org/CVERecord?id=CVE-2019-2848 - https://www.cve.org/CVERecord?id=CVE-2019-2850 - https://www.cve.org/CVERecord?id=CVE-2019-2859 - https://www.cve.org/CVERecord?id=CVE-2019-2863 - https://www.cve.org/CVERecord?id=CVE-2019-2864 - https://www.cve.org/CVERecord?id=CVE-2019-2865 - https://www.cve.org/CVERecord?id=CVE-2019-2866 - https://www.cve.org/CVERecord?id=CVE-2019-2867 - https://www.cve.org/CVERecord?id=CVE-2019-2873 - https://www.cve.org/CVERecord?id=CVE-2019-2874 - https://www.cve.org/CVERecord?id=CVE-2019-2875 - https://www.cve.org/CVERecord?id=CVE-2019-2876 - https://www.cve.org/CVERecord?id=CVE-2019-2877 SRPMS: - 7/core/virtualbox-6.0.10-1.mga7 - 7/core/kmod-virtualbox-6.0.10-1.mga7 - 6/core/virtualbox-6.0.10-1.mga6 - 6/core/kmod-virtualbox-6.0.10-1.mga6 - 6/core/kmod-vboxadditions-6.0.10-1.mga6 . The security notification MGASA-2019-0216 discusses vulnerabilities present in Oracle VM VirtualBox, which could lead to potential data breaches.. virtualbox security, oracle vm, mageia advisories, security updates, information disclosure. . LinuxSecurity.com Team
This update provides an update to the new Virtualbox 6.0 branch, currently 6.0.6. It also fixes the following security issues. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise . MGASA-2019-0151 - Virtualbox 6.0.6 fixes security vulnerabilities Publication date: 04 May 2019 URL: https://advisories.mageia.org/MGASA-2019-0151.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-2574, CVE-2019-2656, CVE-2019-2657, CVE-2019-2678, CVE-2019-2679, CVE-2019-2680, CVE-2019-2690, CVE-2019-2696, CVE-2019-2703, CVE-2019-2721, CVE-2019-2722, CVE-2019-2723 This update provides an update to the new Virtualbox 6.0 branch, currently 6.0.6. It also fixes the following security issues. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data (CVE-2019-2574). Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2019-2656, CVE-2019-2657, CVE-2019-2680, CVE-2019-2696, CVE-2019-2703, CVE-2019-2721, CVE-2019-2722, CVE-2019-2723 Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacksmay significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data (CVE-2019-2678). Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data (CVE-2019-2679). Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox (CVE-2019-2690). For info about other changes in this update, see the referenced changelog. References: - https://bugs.mageia.org/show_bug.cgi?id=24683 - - https://www.oracle.com/security-alerts/cpuapr2019.html - https://www.cve.org/CVERecord?id=CVE-2019-2574 - https://www.cve.org/CVERecord?id=CVE-2019-2656 - https://www.cve.org/CVERecord?id=CVE-2019-2657 - https://www.cve.org/CVERecord?id=CVE-2019-2678 - https://www.cve.org/CVERecord?id=CVE-2019-2679 - https://www.cve.org/CVERecord?id=CVE-2019-2680 - https://www.cve.org/CVERecord?id=CVE-2019-2690 - https://www.cve.org/CVERecord?id=CVE-2019-2696 - https://www.cve.org/CVERecord?id=CVE-2019-2703 - https://www.cve.org/CVERecord?id=CVE-2019-2721 - https://www.cve.org/CVERecord?id=CVE-2019-2722 - https://www.cve.org/CVERecord?id=CVE-2019-2723 SRPMS: - 6/core/kmod-vboxadditions-6.0.6-1.mga6 -6/core/kmod-virtualbox-6.0.6-1.mga6 - 6/core/virtualbox-6.0.6-1.mga6 . A security announcement regarding Mageia's VirtualBox 6.0.6 addresses several flaws that affect data integrity and system performance.. vulnerability management, security advisory, Oracle VM updates, Mageia fixing issues, VirtualBox security. . Severity: Important. LinuxSecurity.com Team
A vulnerability has been discovered in OpenSSL's support for the TLS/DTLS Hearbeat extension. Up to 64KB of memory from either client or server can be recovered by an attacker This vulnerability might allow an attacker to compromise the private key and other sensitive data in . - ------------------------------------------------------------------------- Debian Security Advisory DSA-2896-1
Get the latest Linux and open source security news straight to your inbox.