Home[1] Files[2] News[3] &[SERVICES_TAB] Contact[4] Add New[5]
- Gentoo Linux Security Advisory 202212-03[6]
- Authored by Gentoo[7] | Site security.gentoo.org[8]
-
Gentoo Linux Security Advisory 202212-3 - Multiple vulnerabilities have been discovered in Oracle Virtualbox, the worst of which could result in privilege escalation from a guest to the host. Versions less than 6.1.40 are affected.
- systems | linux[9], gentoo[10]
- advisories | CVE-2022-21620[11], CVE-2022-21621[12], CVE-2022-21627[13], CVE-2022-39421[14], CVE-2022-39422[15], CVE-2022-39423[16], CVE-2022-39424[17], CVE-2022-39425[18], CVE-2022-39426[19]
- SHA-256 |
f263a451255ca7846b6326123bdcb9b57477238f744a30ca91843580d3e34dd5 - Download[20] | Favorite[21] | View[22]
Change Mirror[23] Download[24]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202212-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: Oracle VirtualBox: Multiple Vulnerabilities
Date: December 19, 2022
Bugs: #877601
ID: 202212-03
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
=======
Multiple vulnerabilities have been discovered in Oracle Virtualbox, the
worst of which could result in privilege escalation from a guest to the
host.
Background
=========
VirtualBox is a powerful virtualization product from Oracle.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 app-emulation/virtualbox < 6.1.40 >= 6.1.40
2 app-emulation/virtualbox-modules < 6.1.40 >= 6.1.40
Description
==========
Multiple vulnerabilities have been discovered in Oracle VirtualBox.
Please review the CVE identifiers referenced below for details.
Impact
=====
Please review the referenced CVE identifiers for details.
Workaround
=========
There is no known workaround at this time.
Resolution
=========
All Oracle VirtualBox users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-emulation/virtualbox-6.1.40"
All Oracle VirtualBox modules users should upgrade to the latest
version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=app-emulation/virtualbox-modules-6.1.40"
References
=========
[ 1 ] CVE-2022-21620
https://nvd.nist.gov/vuln/detail/CVE-2022-21620
[ 2 ] CVE-2022-21621
https://nvd.nist.gov/vuln/detail/CVE-2022-21621
[ 3 ] CVE-2022-21627
https://nvd.nist.gov/vuln/detail/CVE-2022-21627
[ 4 ] CVE-2022-39421
https://nvd.nist.gov/vuln/detail/CVE-2022-39421
[ 5 ] CVE-2022-39422
https://nvd.nist.gov/vuln/detail/CVE-2022-39422
[ 6 ] CVE-2022-39423
https://nvd.nist.gov/vuln/detail/CVE-2022-39423
[ 7 ] CVE-2022-39424
https://nvd.nist.gov/vuln/detail/CVE-2022-39424
[ 8 ] CVE-2022-39425
https://nvd.nist.gov/vuln/detail/CVE-2022-39425
[ 9 ] CVE-2022-39426
https://nvd.nist.gov/vuln/detail/CVE-2022-39426
Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202212-03
Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
Cette adresse e-mail est protégée contre les robots spammeurs. Vous devez activer le JavaScript pour la visualiser. or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
======
Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
File Tags
- ActiveX[29] (932)
- Advisory[30] (79,762)
- Arbitrary[31] (15,700)
- BBS[32] (2,859)
- Bypass[33] (1,619)
- CGI[34] (1,018)
- Code Execution[35] (6,928)
- Conference[36] (673)
- Cracker[37] (840)
- CSRF[38] (3,290)
- DoS[39] (22,605)
- Encryption[40] (2,349)
- Exploit[41] (50,363)
- File Inclusion[42] (4,165)
- File Upload[43] (946)
- Firewall[44] (821)
- Info Disclosure[45] (2,662)
- Intrusion Detection[46] (867)
- Java[47] (2,899)
- JavaScript[48] (821)
- Kernel[49] (6,292)
- Local[50] (14,201)
- Magazine[51] (586)
- Overflow[52] (12,419)
- Perl[53] (1,418)
- PHP[54] (5,093)
- Proof of Concept[55] (2,291)
- Protocol[56] (3,435)
- Python[57] (1,467)
- Remote[58] (30,046)
- Root[59] (3,504)
- Ruby[60] (594)
- Scanner[61] (1,631)
- Security Tool[62] (7,777)
- Shell[63] (3,103)
- Shellcode[64] (1,204)
- Sniffer[65] (886)
- Spoof[66] (2,166)
- SQL Injection[67] (16,104)
- TCP[68] (2,379)
- Trojan[69] (686)
- UDP[70] (876)
- Virus[71] (662)
- Vulnerability[72] (31,141)
- Web[73] (9,365)
- Whitepaper[74] (3,729)
- x86[75] (946)
- XSS[76] (17,496)
- Other[77]
File Archives
- December 2022[78]
- November 2022[79]
- October 2022[80]
- September 2022[81]
- August 2022[82]
- July 2022[83]
- June 2022[84]
- May 2022[85]
- April 2022[86]
- March 2022[87]
- February 2022[88]
- January 2022[89]
- Older[90]
Systems
- AIX[91] (426)
- Apple[92] (1,926)
- BSD[93] (370)
- CentOS[94] (55)
- Cisco[95] (1,917)
- Debian[96] (6,636)
- Fedora[97] (1,690)
- FreeBSD[98] (1,242)
- Gentoo[99] (4,277)
- HPUX[100] (878)
- iOS[101] (330)
- iPhone[102] (108)
- IRIX[103] (220)
- Juniper[104] (67)
- Linux[105] (44,323)
- Mac OS X[106] (684)
- Mandriva[107] (3,105)
- NetBSD[108] (255)
- OpenBSD[109] (479)
- RedHat[110] (12,469)
- Slackware[111] (941)
- Solaris[112] (1,607)
- SUSE[113] (1,444)
- Ubuntu[114] (8,200)
- UNIX[115] (9,159)
- UnixWare[116] (185)
- Windows[117] (6,511)
- Other[118]
Read more https://packetstormsecurity.com/files/170305/glsa-202212-03.txt


