Bug 1181198 (CVE-2021-2129) - VUL-0: CVE-2021-2129: virtualbox: core: Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure
Summary: VUL-0: CVE-2021-2129: virtualbox: core: Easily exploitable vulnerability allo...
Status: RESOLVED FIXED
Alias: CVE-2021-2129
Product: openSUSE Distribution
Classification: openSUSE
Component: Basesystem (show other bugs)
Version: Leap 15.2
Hardware: Other Other
: P3 - Medium : Major (vote)
Target Milestone: ---
Assignee: Larry Finger
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/276037/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2021-01-21 07:49 UTC by Alexander Bergmann
Modified: 2023-03-20 19:00 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2021-01-21 07:49:25 UTC
CVE-2021-2129

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core). The supported version that is affected is Prior to 6.1.18.
Easily exploitable vulnerability allows high privileged attacker with logon to
the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM
VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may
significantly impact additional products. Successful attacks of this
vulnerability can result in unauthorized creation, deletion or modification
access to critical data or all Oracle VM VirtualBox accessible data as well as
unauthorized access to critical data or complete access to all Oracle VM
VirtualBox accessible data. CVSS 3.1 Base Score 7.9 (Confidentiality and
Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2021-2129
https://www.oracle.com/security-alerts/cpujan2021.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-2129
Comment 1 Larry Finger 2021-01-21 19:09:34 UTC
Version 6.1.18 has been submitted to Factory about 1 hour ago.
Comment 2 OBSbugzilla Bot 2021-01-22 17:10:12 UTC
This is an autogenerated message for OBS integration:
This bug (1181198) was mentioned in
https://build.opensuse.org/request/show/866079 15.2 / virtualbox
Comment 3 Swamp Workflow Management 2021-01-25 23:17:26 UTC
openSUSE-SU-2021:0165-1: An update that fixes two vulnerabilities is now available.

Category: security (important)
Bug References: 1181197,1181198
CVE References: CVE-2021-2074,CVE-2021-2129
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    virtualbox-6.1.18-lp152.2.11.1, virtualbox-kmp-6.1.18-lp152.2.11.1
Comment 4 Swamp Workflow Management 2021-05-01 01:20:54 UTC
openSUSE-SU-2021:0630-1: An update that solves three vulnerabilities and has two fixes is now available.

Category: security (important)
Bug References: 1181197,1181198,1183125,1183329,1184542
CVE References: CVE-2021-2074,CVE-2021-2129,CVE-2021-2264
JIRA References: 
Sources used:
openSUSE Leap 15.2 (src):    virtualbox-6.1.20-lp152.2.21.1, virtualbox-kmp-6.1.20-lp152.2.21.1
Comment 5 Larry Finger 2023-03-20 18:59:53 UTC
Coode fixing this has been in all versions for some time.
Comment 6 Larry Finger 2023-03-20 19:00:12 UTC
Fixed.