{"id":"MGASA-2015-0228","summary":"Updated virtualbox packages fix security vulnerabilities","details":"Updated virtualbox packages fixes security vulnerability\n\nThis update provides the 4.3.28 maintenance release fixing the\nfollowing security issue:\n\nThe Floppy Disk Controller (FDC) in QEMU, XEN, KVM and virtualbox allows\nlocal guest users to cause a denial of service (out-of-bounds write and\nguest crash) or possibly execute arbitrary code via the FD_CMD_READ_ID,\nFD_CMD_DRIVE_SPECIFICATION_COMMAND, or other unspecified commands,\naka VENOM (CVE-2015-3456).\n\nFor other fixes in the maintenance release, read the referenced changelog.\n","modified":"2026-02-04T03:55:34.177882Z","published":"2015-05-15T18:23:49Z","related":["CVE-2015-3456"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0228.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=15935"},{"type":"REPORT","url":"https://www.virtualbox.org/wiki/Changelog"}],"affected":[{"package":{"name":"kmod-vboxadditions","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/kmod-vboxadditions?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.28-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0228.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.28-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0228.json"}},{"package":{"name":"virtualbox","ecosystem":"Mageia:4","purl":"pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.3.28-1.mga4"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0228.json"}}],"schema_version":"1.7.3","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}