Mageia 2018-0360: virtualbox security update
Summary
This update provides the virtualbox 5.1.18 maintenance release that
fixes atleast the following security issues:
Fixed an easily exploitable vulnerability that allowed unauthenticated
attacker with logon to the infrastructure where Oracle VM VirtualBox
executes to compromise Oracle VM VirtualBox. Successful attacks of this
vulnerability can result in unauthorized ability to cause a partial denial
of service (partial DOS) of Oracle VM VirtualBox (CVE-2018-3005).
Fixed an easily exploitable vulnerability that allowed unauthenticated
attacker with logon to the infrastructure where Oracle VM VirtualBox
executes to compromise Oracle VM VirtualBox. Successful attacks require
human interaction from a person other than the attacker and while the
vulnerability is in Oracle VM VirtualBox, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result
in unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of Oracle VM Vi...
References
- https://bugs.mageia.org/show_bug.cgi?id=23421
- https://www.oracle.com/security-alerts/cpujul2018.html
- - https://www.virtualbox.org/wiki/Changelog#18
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3005
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3055
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3085
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3086
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3087
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3088
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3089
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3090
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-3091
Resolution
MGASA-2018-0360 - Updated virtualbox packages fix security vulnerabilities
SRPMS
- 6/core/virtualbox-5.2.18-1.mga6
- 6/core/kmod-virtualbox-5.2.18-1.mga6
- 6/core/kmod-vboxadditions-5.2.18-1.mga6