Mageia 2020-0180: virtualbox security update
Summary
This update provides the upstream 6.0.20 adding support for kernel 5.6
series and fixes the following security vulnerabilities:
Oracle VM VirtualBox before 6.0.20 has an easily exploitable vulnerability
that allows high privileged attacker with logon to the infrastructure where
Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result in
unauthorized access to critical data or complete access to all Oracle VM
VirtualBox accessible data (CVE-2020-2741).
Oracle VM VirtualBox before 6.0.20 has an easily exploitable vulnerability
that allows high privileged attacker with logon to the infrastructure where
Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly impact
additional products. Successful attacks of this vulnerability can result...
References
- https://bugs.mageia.org/show_bug.cgi?id=26506
- https://www.virtualbox.org/wiki/Changelog-6.0#v20
- https://www.oracle.com/security-alerts/cpuapr2020.html#AppendixOVIR
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2741
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2748
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2758
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2894
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2902
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2905
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2907
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2908
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2909
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2910
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2911
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2913
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2914
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2929
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2951
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2958
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-2959
Resolution
MGASA-2020-0180 - Updated virtualbox packages fix security vulnerabilities
SRPMS
- 7/core/virtualbox-6.0.20-1.mga7
- 7/core/kmod-virtualbox-6.0.20-1.mga7