Detect date
?
|
10/16/2018 |
Severity
?
|
Critical |
Description
|
Multiple serious vulnerabilities were found in Oracle VM Virtual Box. Malicious users can exploit these vulnerabilities to bypass security restrictions, cause denial of service. Below is a complete list of vulnerabilities:
Technical details Vulnerability (3) is related to OpenSSL vulnerability (Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2-1.0.2o)). During key agreement in a TLS handshake using a DH(E) based ciphersuite a malicious server can send a very large prime value to the client. This will cause the client to spend an unreasonably long period of time generating a key for this prime resulting in a hang until the client has finished. |
Affected products
|
Oracle VM Virtual Box versions earlier than 5.2.20 |
Solution
|
Update to the latest version |
Original advisories
|
|
Impacts
?
|
DoS [?] SB [?] |
Related products
|
Oracle VirtualBox |
CVE-IDS
?
|
CVE-2018-32946.0High
CVE-2018-32884.4Warning CVE-2018-32894.4Warning CVE-2018-32904.4Warning CVE-2018-32964.4Warning CVE-2018-32974.4Warning CVE-2018-29094.4Warning CVE-2018-32984.4Warning CVE-2018-32914.4Warning CVE-2018-32924.4Warning CVE-2018-32934.4Warning CVE-2018-32954.4Warning CVE-2018-32874.4Warning CVE-2018-07325.0Critical |
Find out the statistics of the vulnerabilities spreading in your region |