Gentoo Archives: gentoo-announce

From: Kristian Fiskerstrand <k_f@g.o>
To: gentoo-announce@l.g.o
Subject: [gentoo-announce] [ GLSA 201612-27 ] VirtualBox: Multiple vulnerabilities
Date: Mon, 12 Dec 2016 00:25:15
Message-Id: 84d7f28a-6b06-af16-83ad-f33a7ecd46fc@gentoo.org
1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
2 Gentoo Linux Security Advisory GLSA 201612-27
3 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
4 https://security.gentoo.org/
5 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
6
7 Severity: Normal
8 Title: VirtualBox: Multiple vulnerabilities
9 Date: December 11, 2016
10 Bugs: #505274, #537218, #550964
11 ID: 201612-27
12
13 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
14
15 Synopsis
16 ========
17
18 Multiple vulnerabilities have been found in VirtualBox, the worst of
19 which allows local users to escalate privileges.
20
21 Background
22 ==========
23
24 VirtualBox is a powerful virtualization product from Oracle.
25
26 Affected packages
27 =================
28
29 -------------------------------------------------------------------
30 Package / Vulnerable / Unaffected
31 -------------------------------------------------------------------
32 1 app-emulation/virtualbox
33 < 4.3.28 >= 4.3.28
34 2 app-emulation/virtualbox-bin
35 < 4.3.28 >= 4.3.28
36 -------------------------------------------------------------------
37 2 affected packages
38
39 Description
40 ===========
41
42 Multiple vulnerabilities have been discovered in VirtualBox. Please
43 review the CVE identifiers referenced below for details.
44
45 Impact
46 ======
47
48 Local attackers could cause a Denial of Service condition, execute
49 arbitrary code, or escalate their privileges.
50
51 Workaround
52 ==========
53
54 There is no known workaround at this time.
55
56 Resolution
57 ==========
58
59 All VirtualBox users should upgrade to the latest version:
60
61 # emerge --sync
62 # emerge --ask --oneshot -v ">=app-emulation/virtualbox-4.3.28"
63
64 All VirtualBox-bin users should upgrade to the latest version:
65
66 # emerge --sync
67 # emerge --ask --oneshot -v ">=app-emulation/virtualbox-bin-4.3.28"
68
69 References
70 ==========
71
72 [ 1 ] CVE-2014-0981
73 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0981
74 [ 2 ] CVE-2014-0983
75 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-0983
76 [ 3 ] CVE-2014-6588
77 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6588
78 [ 4 ] CVE-2014-6589
79 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6589
80 [ 5 ] CVE-2014-6590
81 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6590
82 [ 6 ] CVE-2014-6595
83 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-6595
84 [ 7 ] CVE-2015-0377
85 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0377
86 [ 8 ] CVE-2015-0418
87 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0418
88 [ 9 ] CVE-2015-0427
89 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-0427
90 [ 10 ] CVE-2015-3456
91 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2015-3456
92 [ 11 ] CVE-2016-5608
93 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5608
94 [ 12 ] CVE-2016-5610
95 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5610
96 [ 13 ] CVE-2016-5611
97 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5611
98 [ 14 ] CVE-2016-5613
99 http://nvd.nist.gov/nvd.cfm?cvename=CVE-2016-5613
100
101 Availability
102 ============
103
104 This GLSA and any updates to it are available for viewing at
105 the Gentoo Security Website:
106
107 https://security.gentoo.org/glsa/201612-27
108
109 Concerns?
110 =========
111
112 Security is a primary focus of Gentoo Linux and ensuring the
113 confidentiality and security of our users' machines is of utmost
114 importance to us. Any security concerns should be addressed to
115 security@g.o or alternatively, you may file a bug at
116 https://bugs.gentoo.org.
117
118 License
119 =======
120
121 Copyright 2016 Gentoo Foundation, Inc; referenced text
122 belongs to its owner(s).
123
124 The contents of this document are licensed under the
125 Creative Commons - Attribution / Share Alike license.
126
127 http://creativecommons.org/licenses/by-sa/2.5

Attachments

File name MIME type
signature.asc application/pgp-signature