{"id":"MGASA-2015-0415","summary":"Updated virtualbox packages fix security vulnerabilities","details":"A vulnerability in the Oracle VM VirtualBox component prior to 4.0.34,\n4.1.42, 4.2.34, 4.3.32 and 5.0.8. Easily exploitable vulnerability\nrequiring logon to Operating System. Successful attack of this\nvulnerability can result in unauthorized ability to cause a hang or\nfrequently repeatable crash (complete DOS). \nNote: Only Windows guests are impacted, and Windows guests without\nVirtualBox Guest Additions installed are not affected (CVE-2015-4813).\n\nA vulnerability in the Oracle VM VirtualBox component prior to 4.0.34,\n4.1.42, 4.2.34, 4.3.32 and 5.0.8. Easily exploitable vulnerability allows\nsuccessful unauthenticated network attacks. Successful attack of this\nvulnerability can result in unauthorized ability to cause a hang or\nfrequently repeatable crash (complete DOS).\nNote: Only VMs with Remote Display feature (RDP) enabled are impacted\n(CVE-2015-4896).\n\nFor other fixes in this update, see the referenced changelog.\n","modified":"2026-04-16T06:26:21.033517009Z","published":"2015-10-27T09:06:52Z","upstream":["CVE-2015-4813","CVE-2015-4896"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2015-0415.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=17015"},{"type":"WEB","url":"http://www.oracle.com/technetwork/topics/security/cpuoct2015-2367953.html#AppendixOVIR"},{"type":"WEB","url":"https://www.virtualbox.org/wiki/Changelog"}],"affected":[{"package":{"name":"kmod-vboxadditions","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-vboxadditions?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.8-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0415.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.8-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0415.json"}},{"package":{"name":"virtualbox","ecosystem":"Mageia:5","purl":"pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.0.8-1.mga5"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2015-0415.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}