Bug 1181197 (CVE-2021-2074) - VUL-0: CVE-2021-2074: virtualbox: core: Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure
Summary: VUL-0: CVE-2021-2074: virtualbox: core: Easily exploitable vulnerability allo...
Status: RESOLVED FIXED
Alias: CVE-2021-2074
Product: openSUSE Distribution
Classification: openSUSE
Component: Basesystem (show other bugs)
Version: Leap 15.2
Hardware: Other Other
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Larry Finger
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/275982/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-01-21 07:48 UTC by Alexander Bergmann
Modified: 2023-03-20 19:01 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-01-21 07:48:44 UTC
CVE-2021-2074

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core). The supported version that is affected is Prior to 6.1.18.
Easily exploitable vulnerability allows high privileged attacker with logon to
the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM
VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may
significantly impact additional products. Successful attacks of this
vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base
Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector:
(CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-2074
https://www.oracle.com/security-alerts/cpujan2021.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2074
Comment 1 Larry Finger 2021-01-21 19:08:09 UTC
Version 6.1.18 submitted to Factory about 1 hour ago.
Comment 2 OBSbugzilla Bot 2021-01-22 17:10:07 UTC
This is an autogenerated message for OBS integration:
This bug (1181197) was mentioned in
https://build.opensuse.org/request/show/866079 15.2 / virtualbox
Comment 3 Swamp Workflow Management 2021-01-25 23:17:20 UTC
openSUSE-SU-2021:0165-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1181197,1181198
CVE References: CVE-2021-2074,CVE-2021-2129
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    virtualbox-6.1.18-lp152.2.11.1, virtualbox-kmp-6.1.18-lp152.2.11.1
Comment 4 Swamp Workflow Management 2021-05-01 01:20:49 UTC
openSUSE-SU-2021:0630-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1181197,1181198,1183125,1183329,1184542
CVE References: CVE-2021-2074,CVE-2021-2129,CVE-2021-2264
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    virtualbox-6.1.20-lp152.2.21.1, virtualbox-kmp-6.1.20-lp152.2.21.1
Comment 5 Larry Finger 2023-03-20 19:01:15 UTC
Code fixing this in all versions.