Búsqueda de    
Vulnerabilidad   
    Buscar 219043 Descripciones CVE y
99761 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.851686
Categoría:SuSE Local Security Checks
Título:openSUSE: Security Advisory for virtualbox (openSUSE-SU-2018:0187-1)
Resumen:The remote host is missing an update for the 'virtualbox'; package(s) announced via the referenced advisory.
Descripción:Summary:
The remote host is missing an update for the 'virtualbox'
package(s) announced via the referenced advisory.

Vulnerability Insight:
This update for virtualbox to version 5.1.32 fixes the following issues:

The following vulnerabilities were fixed (boo#1076372):

- CVE-2017-5715: Systems with microprocessors utilizing speculative
execution and indirect branch prediction may allow unauthorized
disclosure of information to an attacker with local user access via a
side-channel analysis, also known as 'Spectre', bsc#1068032.

- CVE-2018-2676: Local authenticated attacker may gain elevated privileges

- CVE-2018-2685: Local authenticated attacker may gain elevated privileges

- CVE-2018-2686: Local authenticated attacker may gain elevated privileges

- CVE-2018-2687: Local authenticated attacker may gain elevated privileges

- CVE-2018-2688: Local authenticated attacker may gain elevated privileges

- CVE-2018-2689: Local authenticated attacker may gain elevated privileges

- CVE-2018-2690: Local authenticated attacker may gain elevated privileges

- CVE-2018-2693: Local authenticated attacker may gain elevated privileges
via guest additions

- CVE-2018-2694: Local authenticated attacker may gain elevated privileges

- CVE-2018-2698: Local authenticated attacker may gain elevated privileges

The following bug fixes are included:

- fix occasional screen corruption when host screen resolution is changed

- increase proposed disk size when creating new VMs for Windows 7 and newer

- fix broken communication with certain devices on Linux hosts

- Fix problems using 256MB VRAM in raw-mode VMs

- add HDA support for more exotic guests (e.g. Haiku)

- fix playback with ALSA backend (5.1.28 regression)

- fix a problem where OHCI emulation might sporadically drop data transfers

Affected Software/OS:
virtualbox on openSUSE Leap 42.3, openSUSE Leap 42.2

Solution:
Please install the updated package(s).

CVSS Score:
4.4

CVSS Vector:
AV:L/AC:M/Au:N/C:P/I:P/A:P

Referencia Cruzada: Common Vulnerability Exposure (CVE) ID: CVE-2017-5715
BugTraq ID: 102376
http://www.securityfocus.com/bid/102376
Bugtraq: 20190624 [SECURITY] [DSA 4469-1] libvirt security update (Google Search)
https://seclists.org/bugtraq/2019/Jun/36
Bugtraq: 20191112 FreeBSD Security Advisory FreeBSD-SA-19:26.mcu (Google Search)
https://seclists.org/bugtraq/2019/Nov/16
CERT/CC vulnerability note: VU#180049
https://www.kb.cert.org/vuls/id/180049
CERT/CC vulnerability note: VU#584653
http://www.kb.cert.org/vuls/id/584653
Cisco Security Advisory: 20180104 CPU Side-Channel Information Disclosure Vulnerabilities
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20180104-cpusidechannel
Debian Security Information: DSA-4120 (Google Search)
https://www.debian.org/security/2018/dsa-4120
Debian Security Information: DSA-4187 (Google Search)
https://www.debian.org/security/2018/dsa-4187
Debian Security Information: DSA-4188 (Google Search)
https://www.debian.org/security/2018/dsa-4188
Debian Security Information: DSA-4213 (Google Search)
https://www.debian.org/security/2018/dsa-4213
https://www.exploit-db.com/exploits/43427/
FreeBSD Security Advisory: FreeBSD-SA-19:26
https://security.FreeBSD.org/advisories/FreeBSD-SA-18:03.speculative_execution.asc
https://security.FreeBSD.org/advisories/FreeBSD-SA-19:26.mcu.asc
https://security.gentoo.org/glsa/201810-06
http://packetstormsecurity.com/files/145645/Spectre-Information-Disclosure-Proof-Of-Concept.html
http://packetstormsecurity.com/files/155281/FreeBSD-Security-Advisory-FreeBSD-SA-19-26.mcu.html
https://googleprojectzero.blogspot.com/2018/01/reading-privileged-memory-with-side.html
https://security.googleblog.com/2018/01/todays-cpu-vulnerability-what-you-need.html
https://spectreattack.com/
https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html
https://lists.debian.org/debian-lts-announce/2018/05/msg00000.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00015.html
https://lists.debian.org/debian-lts-announce/2018/07/msg00016.html
https://lists.debian.org/debian-lts-announce/2018/09/msg00007.html
https://lists.debian.org/debian-lts-announce/2018/09/msg00017.html
https://lists.debian.org/debian-lts-announce/2020/03/msg00025.html
https://lists.debian.org/debian-lts-announce/2021/08/msg00019.html
RedHat Security Advisories: RHSA-2018:0292
https://access.redhat.com/errata/RHSA-2018:0292
http://www.securitytracker.com/id/1040071
SuSE Security Announcement: SUSE-SU-2018:0006 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00002.html
SuSE Security Announcement: SUSE-SU-2018:0007 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00003.html
SuSE Security Announcement: SUSE-SU-2018:0008 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00004.html
SuSE Security Announcement: SUSE-SU-2018:0009 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00005.html
SuSE Security Announcement: SUSE-SU-2018:0010 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00006.html
SuSE Security Announcement: SUSE-SU-2018:0011 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00007.html
SuSE Security Announcement: SUSE-SU-2018:0012 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00008.html
SuSE Security Announcement: SUSE-SU-2018:0019 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00012.html
SuSE Security Announcement: SUSE-SU-2018:0020 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00013.html
SuSE Security Announcement: openSUSE-SU-2018:0013 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00009.html
SuSE Security Announcement: openSUSE-SU-2018:0022 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00014.html
SuSE Security Announcement: openSUSE-SU-2018:0023 (Google Search)
http://lists.opensuse.org/opensuse-security-announce/2018-01/msg00016.html
https://usn.ubuntu.com/usn/usn-3516-1/
https://usn.ubuntu.com/3531-1/
https://usn.ubuntu.com/3531-3/
https://usn.ubuntu.com/3540-2/
https://usn.ubuntu.com/3541-2/
https://usn.ubuntu.com/3542-2/
https://usn.ubuntu.com/3549-1/
https://usn.ubuntu.com/3560-1/
https://usn.ubuntu.com/3561-1/
https://usn.ubuntu.com/3580-1/
https://usn.ubuntu.com/3581-1/
https://usn.ubuntu.com/3581-2/
https://usn.ubuntu.com/3582-1/
https://usn.ubuntu.com/3582-2/
https://usn.ubuntu.com/3594-1/
https://usn.ubuntu.com/3597-1/
https://usn.ubuntu.com/3597-2/
https://usn.ubuntu.com/3620-2/
https://usn.ubuntu.com/3690-1/
https://usn.ubuntu.com/3777-3/
Common Vulnerability Exposure (CVE) ID: CVE-2018-2676
BugTraq ID: 102699
http://www.securityfocus.com/bid/102699
http://www.securitytracker.com/id/1040202
Common Vulnerability Exposure (CVE) ID: CVE-2018-2685
BugTraq ID: 102689
http://www.securityfocus.com/bid/102689
Common Vulnerability Exposure (CVE) ID: CVE-2018-2686
BugTraq ID: 102690
http://www.securityfocus.com/bid/102690
Common Vulnerability Exposure (CVE) ID: CVE-2018-2687
BugTraq ID: 102691
http://www.securityfocus.com/bid/102691
Common Vulnerability Exposure (CVE) ID: CVE-2018-2688
BugTraq ID: 102692
http://www.securityfocus.com/bid/102692
Common Vulnerability Exposure (CVE) ID: CVE-2018-2689
BugTraq ID: 102693
http://www.securityfocus.com/bid/102693
Common Vulnerability Exposure (CVE) ID: CVE-2018-2690
BugTraq ID: 102694
http://www.securityfocus.com/bid/102694
Common Vulnerability Exposure (CVE) ID: CVE-2018-2693
BugTraq ID: 102702
http://www.securityfocus.com/bid/102702
Common Vulnerability Exposure (CVE) ID: CVE-2018-2694
BugTraq ID: 102687
http://www.securityfocus.com/bid/102687
Common Vulnerability Exposure (CVE) ID: CVE-2018-2698
BugTraq ID: 102688
http://www.securityfocus.com/bid/102688
https://www.exploit-db.com/exploits/43878/
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

Esta es sólo una de 99761 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2024 E-Soft Inc. Todos los derechos reservados.