Mageia 2019-0216: virtualbox security update
Summary
OpenSSL versions 1.1.0 through 1.1.0j and 1.1.1 through 1.1.1b are
susceptible to a vulnerability that could lead to disclosure of sensitive
information or the addition or modification of data (CVE-2019-1543).
Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability
that allows low privileged attacker with logon to the infrastructure where
Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result in
unauthorized ability to cause a hang or frequently repeatable crash
(complete DOS) of Oracle VM VirtualBox (CVE-2019-2848).
Oracle VM VirtualBox prior to 6.0.10 has an easily exploitable vulnerability
that allows low privileged attacker with logon to the infrastructure where
Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful
attacks require human interaction from a person other t...
References
- https://bugs.mageia.org/show_bug.cgi?id=25161
- https://www.oracle.com/security-alerts/cpujul2019.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1543
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2848
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2850
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2859
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2863
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2864
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2865
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2866
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2867
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2873
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2874
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2875
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2876
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2877
Resolution
MGASA-2019-0216 - Updated virtualbox packages fix security vulnerabilities
SRPMS
- 7/core/virtualbox-6.0.10-1.mga7
- 7/core/kmod-virtualbox-6.0.10-1.mga7
- 6/core/virtualbox-6.0.10-1.mga6
- 6/core/kmod-virtualbox-6.0.10-1.mga6
- 6/core/kmod-vboxadditions-6.0.10-1.mga6