{"id":"MGASA-2018-0257","summary":"Updated virtualbox packages fix security vulnerabilities","details":"This update provides virtualbox 5.2.12 and fixes the following security\nissues:\n\nUnauthorized remote attacker may have caused a hang or frequently\nrepeatable crash (complete DOS) (CVE-2018-0739).\n\nAttacker with host login may have compromised Virtualbox or further system\nservices after interaction with a third user (CVE-2018-2830).\n\nAttacker with host login may have compromised VirtualBox or further system\nservices, allowing read access to some data (CVE-2018-2831).\n\nAttacker with host login may have gained control over VirtualBox and\npossibly further system services after interacting with a third user\n(CVE-2018-2835, CVE-2018-2836, CVE-2018-2837, CVE-2018-2842,\nCVE-2018-2843, CVE-2018-2844).\n\nAttacker with host login may have caused a hang or frequently repeatable\ncrash (complete DOS), and perform unauthorized read and write operation\nto some VirtualBox accessible data (CVE-2018-2845).\n\nPrivileged attacker may have gained control over VirtualBox and possibly\nfurther system services (CVE-2018-2860).\n\nFor other fixes in this update, see the referenced changelog \n","modified":"2026-04-16T06:23:46.033393935Z","published":"2018-05-29T19:41:14Z","upstream":["CVE-2018-0739","CVE-2018-2830","CVE-2018-2831","CVE-2018-2835","CVE-2018-2836","CVE-2018-2837","CVE-2018-2842","CVE-2018-2843","CVE-2018-2844","CVE-2018-2845","CVE-2018-2860"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2018-0257.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=22930"},{"type":"WEB","url":"https://www.virtualbox.org/wiki/Changelog"},{"type":"ADVISORY","url":"http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html#AppendixOVIR"}],"affected":[{"package":{"name":"virtualbox","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.12-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0257.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.12-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0257.json"}},{"package":{"name":"kmod-vboxadditions","ecosystem":"Mageia:6","purl":"pkg:rpm/mageia/kmod-vboxadditions?arch=source&distro=mageia-6"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.2.12-1.mga6"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2018-0257.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}