KLA11641
Multiple vulnerabilities in Oracle VirtualBox
Updated: 01/24/2020
Detect date
?
01/05/2020
Severity
?
Warning
Description

Multiple vulnerabilities were found in Oracle VirtualBox. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information, bypass security restrictions, cause denial of service.
  2. Vulnerability in Web Services (Apache Axis) component of Oracle Secure Global Desktop can be exploited remotely to obtain sensitive information, bypass security restrictions, cause denial of service.
  3. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to cause denial of service.
  4. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information.
  5. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information, bypass security restrictions.
  6. Vulnerability in Core (Mojarra) component of Oracle Secure Global Desktop can be exploited remotely to obtain sensitive information, bypass security restrictions.
  7. Vulnerability in Web Server (Apache HTTPD Server) component of Oracle Secure Global Desktop can be exploited remotely to obtain sensitive information, bypass security restrictions.
  8. Vulnerability in Core(OpenSSL) component of Oracle VM VirtualBox can be exploited to bypass security restrictions;
Affected products

Oracle VirtualBox 5.2.x up to 5.2.36
Oracle VirtualBox 6.0.x up to 6.0.16
Oracle VirtualBox 6.1.x up to 6.1.2

Solution

Update to the latest version
Download Oracle Virtual Box

Original advisories

Oracle Critical Patch Update Advisory – January 2020

Impacts
?
OSI 
[?]

DoS 
[?]

SB 
[?]
Related products
Oracle VirtualBox
CVE-IDS
?
CVE-2019-15470.0Unknown
CVE-2020-26740.0Unknown
CVE-2020-26820.0Unknown
CVE-2019-02270.0Unknown
CVE-2020-26980.0Unknown
CVE-2020-27010.0Unknown
CVE-2020-27020.0Unknown
CVE-2020-27260.0Unknown
CVE-2020-26810.0Unknown
CVE-2020-26890.0Unknown
CVE-2020-26900.0Unknown
CVE-2020-26910.0Unknown
CVE-2020-26920.0Unknown
CVE-2020-27030.0Unknown
CVE-2020-27040.0Unknown
CVE-2020-27050.0Unknown
CVE-2020-27250.0Unknown
CVE-2020-26780.0Unknown
CVE-2019-170910.0Unknown
CVE-2020-27270.0Unknown
CVE-2020-26930.0Unknown
CVE-2019-100920.0Unknown