Lucene search

K
suseSuseOPENSUSE-SU-2017:0382-1
HistoryFeb 04, 2017 - 3:07 a.m.

Security update for virtualbox (important)

2017-02-0403:07:22
lists.opensuse.org
39

EPSS

0.022

Percentile

89.6%

This update for virtualbox to version 5.1.14 fixes the following issues:

These security issues were fixed:

  • CVE-2016-5545: Vulnerability in the GUI subcomponent of virtualbox
    allows unauthenticated attacker unauthorized update, insert or delete
    access to some data as well as unauthorized read access to a subset of
    VirtualBox accessible data and unauthorized ability to cause a partial
    denial of service (bsc#1020856).
  • CVE-2017-3290: Vulnerability in the Shared Folder subcomponent of
    virtualbox allows high privileged attacker unauthorized creation,
    deletion or modification access to critical data and unauthorized
    ability to cause a hang or frequently repeatable crash (bsc#1020856).
  • CVE-2017-3316: Vulnerability in the GUI subcomponent of virtualbox
    allows high privileged attacker with network access via multiple
    protocols to compromise Oracle VM VirtualBox (bsc#1020856).
  • CVE-2017-3332: Vulnerability in the SVGA Emulation subcomponent of
    virtualbox allows low privileged attacker unauthorized creation,
    deletion or modification access to critical data and unauthorized
    ability to cause a hang or frequently repeatable crash (bsc#1020856).

For other changes please read the changelog.