Gentoo Archives: gentoo-announce

From: Thomas Deutschmann <whissi@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201802-01 ] VirtualBox: Multiple vulnerabilities
Date: Sun, 11 Feb 2018 22:42:43
Message-Id: 200ba31f-6c0a-1351-2116-5855effc446d@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201802-01
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: High
8 Title: VirtualBox: Multiple vulnerabilities
9 Date: February 11, 2018
10 Bugs: #644894
11 ID: 201802-01
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in VirtualBox, the worst of
19 which could allow an attacker to take control of VirtualBox.
20
21 Background
22 ==========
23
24 VirtualBox is a powerful virtualization product from Oracle.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 app-emulation/virtualbox
33 < 5.1.32 >= 5.1.32
34 2 app-emulation/virtualbox-bin
35 < 5.1.32.120294 >= 5.1.32.120294
36 3 app-emulation/virtualbox-guest-additions
37 < 5.1.32 >= 5.1.32
38 -------------------------------------------------------------------
39 3 affected packages
40
41 Description
42 ===========
43
44 Multiple vulnerabilities have been discovered in VirtualBox. Please
45 review the CVE identifiers referenced below for details.
46
47 Impact
48 ======
49
50 An attacker could take control of VirtualBox resulting in the execution
51 of arbitrary code with the privileges of the process, a Denial of
52 Service condition, or other unspecified impacts.
53
54 Workaround
55 ==========
56
57 There is no known workaround at this time.
58
59 Resolution
60 ==========
61
62 All VirtualBox users should upgrade to the latest version:
63
64 # emerge --sync
65 # emerge --ask --oneshot -v ">=app-emulation/virtualbox-5.1.32"
66
67 All VirtualBox Binary users should upgrade to the latest version:
68
69 # emerge --sync
70 # emerge -a -1 -v ">=app-emulation/virtualbox-bin-5.1.32.120294"
71
72 All VirtualBox Guest Additions users should upgrade to the latest
73 version:
74
75 # emerge --sync
76 # emerge -a -1 -v ">=app-emulation/virtualbox-guest-additions-5.1.32"
77
78 References
79 ==========
80
81 [ 1 ] CVE-2018-2676
82 https://nvd.nist.gov/vuln/detail/CVE-2018-2676
83 [ 2 ] CVE-2018-2685
84 https://nvd.nist.gov/vuln/detail/CVE-2018-2685
85 [ 3 ] CVE-2018-2686
86 https://nvd.nist.gov/vuln/detail/CVE-2018-2686
87 [ 4 ] CVE-2018-2687
88 https://nvd.nist.gov/vuln/detail/CVE-2018-2687
89 [ 5 ] CVE-2018-2688
90 https://nvd.nist.gov/vuln/detail/CVE-2018-2688
91 [ 6 ] CVE-2018-2689
92 https://nvd.nist.gov/vuln/detail/CVE-2018-2689
93 [ 7 ] CVE-2018-2690
94 https://nvd.nist.gov/vuln/detail/CVE-2018-2690
95 [ 8 ] CVE-2018-2693
96 https://nvd.nist.gov/vuln/detail/CVE-2018-2693
97 [ 9 ] CVE-2018-2694
98 https://nvd.nist.gov/vuln/detail/CVE-2018-2694
99 [ 10 ] CVE-2018-2698
100 https://nvd.nist.gov/vuln/detail/CVE-2018-2698
101
102 Availability
103 ============
104
105 This GLSA and any updates to it are available for viewing at
106 the Gentoo Security Website:
107
108 https://security.gentoo.org/glsa/201802-01
109
110 Concerns?
111 =========
112
113 Security is a primary focus of Gentoo Linux and ensuring the
114 confidentiality and security of our users' machines is of utmost
115 importance to us. Any security concerns should be addressed to
116 security@g.o or alternatively, you may file a bug at
117 https://bugs.gentoo.org.
118
119 License
120 =======
121
122 Copyright 2018 Gentoo Foundation, Inc; referenced text
123 belongs to its owner(s).
124
125 The contents of this document are licensed under the
126 Creative Commons - Attribution / Share Alike license.
127
128 https://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature