MGASA-2015-0415

Source
https://advisories.mageia.org/MGASA-2015-0415.html
Import Source
https://advisories.mageia.org/MGASA-2015-0415.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0415
Related
  • CVE-2015-4813
  • CVE-2015-4896
Published
2015-10-27T09:06:52Z
Modified
2015-10-27T09:03:27Z
Summary
Updated virtualbox packages fix security vulnerabilities
Details

A vulnerability in the Oracle VM VirtualBox component prior to 4.0.34, 4.1.42, 4.2.34, 4.3.32 and 5.0.8. Easily exploitable vulnerability requiring logon to Operating System. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS). Note: Only Windows guests are impacted, and Windows guests without VirtualBox Guest Additions installed are not affected (CVE-2015-4813).

A vulnerability in the Oracle VM VirtualBox component prior to 4.0.34, 4.1.42, 4.2.34, 4.3.32 and 5.0.8. Easily exploitable vulnerability allows successful unauthenticated network attacks. Successful attack of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS). Note: Only VMs with Remote Display feature (RDP) enabled are impacted (CVE-2015-4896).

For other fixes in this update, see the referenced changelog.

References
Credits

Affected packages

Mageia:5 / kmod-vboxadditions

Package

Name
kmod-vboxadditions
Purl
pkg:rpm/mageia/kmod-vboxadditions?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.8-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.8-1.mga5

Ecosystem specific

{
    "section": "core"
}

Mageia:5 / virtualbox

Package

Name
virtualbox
Purl
pkg:rpm/mageia/virtualbox?distro=mageia-5

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.8-1.mga5

Ecosystem specific

{
    "section": "core"
}