[manjaro-security] [ASA-202104-9] virtualbox: multiple issues

Santiago Torres-Arias via arch-security arch-security at lists.archlinux.org
Thu Apr 29 23:46:28 CEST 2021


Arch Linux Security Advisory ASA-202104-9
=========================================

Severity: High
Date    : 2021-04-29
CVE-ID  : CVE-2021-2145 CVE-2021-2250 CVE-2021-2266 CVE-2021-2279
          CVE-2021-2280 CVE-2021-2281 CVE-2021-2282 CVE-2021-2283
          CVE-2021-2284 CVE-2021-2285 CVE-2021-2286 CVE-2021-2287
          CVE-2021-2291 CVE-2021-2296 CVE-2021-2297 CVE-2021-2306
          CVE-2021-2309 CVE-2021-2310 CVE-2021-2321
Package : virtualbox
Type    : multiple issues
Remote  : Yes
Link    : https://security.archlinux.org/AVG-1846

Summary
=======

The package virtualbox before version 6.1.20-1 is vulnerable to
multiple issues including arbitrary code execution, arbitrary
filesystem access and information disclosure.

Resolution
==========

Upgrade to 6.1.20-1.

# pacman -Syu "virtualbox>=6.1.20-1"

The problems have been fixed upstream in version 6.1.20.

Workaround
==========

None.

Description
===========

- CVE-2021-2145 (arbitrary code execution)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in takeover of Oracle VM VirtualBox.

- CVE-2021-2250 (arbitrary code execution)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in takeover of Oracle VM VirtualBox.

- CVE-2021-2266 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2279 (arbitrary code execution)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
unauthenticated attacker with network access via RDP to compromise
Oracle VM VirtualBox. Successful attacks of this vulnerability can
result in takeover of Oracle VM VirtualBox.

- CVE-2021-2280 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2281 (arbitrary filesystem access)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized creation, deletion or modification access to
critical data or all Oracle VM VirtualBox accessible data.

- CVE-2021-2282 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2283 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2284 (arbitrary filesystem access)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized creation, deletion or modification access to
critical data or all Oracle VM VirtualBox accessible data.

- CVE-2021-2285 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2286 (arbitrary filesystem access)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized creation, deletion or modification access to
critical data or all Oracle VM VirtualBox accessible data.

- CVE-2021-2287 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
unauthenticated attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2291 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
low privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful
attacks of this vulnerability can result in unauthorized access to
critical data or complete access to all Oracle VM VirtualBox accessible
data.

- CVE-2021-2296 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2297 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2306 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

- CVE-2021-2309 (arbitrary code execution)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in takeover of Oracle VM VirtualBox.

- CVE-2021-2310 (arbitrary code execution)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Difficult to exploit vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in takeover of Oracle VM VirtualBox.

- CVE-2021-2321 (information disclosure)

Vulnerability in the Oracle VM VirtualBox product of Oracle
Virtualization (component: Core). The supported version that is
affected is Prior to 6.1.20. Easily exploitable vulnerability allows
high privileged attacker with logon to the infrastructure where Oracle
VM VirtualBox executes to compromise Oracle VM VirtualBox. While the
vulnerability is in Oracle VM VirtualBox, attacks may significantly
impact additional products. Successful attacks of this vulnerability
can result in unauthorized access to critical data or complete access
to all Oracle VM VirtualBox accessible data.

Impact
======

An attacker is able to execute arbitrary code, read sensitive
information, and read filesystem information through various means.

References
==========

https://www.oracle.com/security-alerts/cpuapr2021verbose.html#OVIR
https://security.archlinux.org/CVE-2021-2145
https://security.archlinux.org/CVE-2021-2250
https://security.archlinux.org/CVE-2021-2266
https://security.archlinux.org/CVE-2021-2279
https://security.archlinux.org/CVE-2021-2280
https://security.archlinux.org/CVE-2021-2281
https://security.archlinux.org/CVE-2021-2282
https://security.archlinux.org/CVE-2021-2283
https://security.archlinux.org/CVE-2021-2284
https://security.archlinux.org/CVE-2021-2285
https://security.archlinux.org/CVE-2021-2286
https://security.archlinux.org/CVE-2021-2287
https://security.archlinux.org/CVE-2021-2291
https://security.archlinux.org/CVE-2021-2296
https://security.archlinux.org/CVE-2021-2297
https://security.archlinux.org/CVE-2021-2306
https://security.archlinux.org/CVE-2021-2309
https://security.archlinux.org/CVE-2021-2310
https://security.archlinux.org/CVE-2021-2321

-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 833 bytes
Desc: not available
URL: <http://lists.manjaro.org/pipermail/manjaro-security/attachments/20210429/28007876/attachment-0001.sig>


More information about the manjaro-security mailing list