Bug 990369 (CVE-2016-3612) - VUL-0: CVE-2016-3612: virtualbox: unspecified vulnerability
Summary: VUL-0: CVE-2016-3612: virtualbox: unspecified vulnerability
Status: RESOLVED FIXED
Alias: CVE-2016-3612
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 42.1
: P5 - None : Normal
Target Milestone: ---
Assignee: Larry Finger
QA Contact: Security Team bot
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2016-07-23 18:20 UTC by Andreas Stieger
Modified: 2016-10-09 18:40 UTC (History)
1 user (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Andreas Stieger 2016-07-23 18:20:01 UTC
http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html#AppendixOVIR

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is VirtualBox prior to 5.0.22. Difficult to exploit vulnerability allows unauthenticated attacker with network access via SSL/TLS to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle VM VirtualBox accessible data.

CVSS v3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). 

The fix for CVE-2016-3612 also addresses CVE-2016-2105, CVE-2016-2106, CVE-2016-2107, CVE-2016-2109, and CVE-2016-2176.
Comment 1 Andreas Stieger 2016-07-23 18:21:25 UTC
This one is already fixed in openSUSE Leap 42.1 which is at 5.0.24.
This remains unfixed in openSUSE 13.2 which is as 5.0.20.
Comment 2 Swamp Workflow Management 2016-09-15 15:11:57 UTC
openSUSE-SU-2016:2314-1: An update that solves two vulnerabilities and has one errata is now available.

Category: security (moderate)
Bug References: 983927,990369,990370
CVE References: CVE-2016-3597,CVE-2016-3612
Sources used:
openSUSE 13.2 (src):    virtualbox-5.0.26-51.1
Comment 3 Larry Finger 2016-10-09 18:40:47 UTC
Fixed in 5.0.26.