KLA11641
Multiple vulnerabilities in Oracle VirtualBox
Обновлено: 17/01/2020
Дата обнаружения
05/01/2020
Уровень угрозы
Warning
Описание

Multiple vulnerabilities were found in Oracle VirtualBox. Malicious users can exploit these vulnerabilities to obtain sensitive information, cause denial of service, bypass security restrictions.

Below is a complete list of vulnerabilities:

  1. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information, bypass security restrictions, cause denial of service.
  2. Vulnerability in Web Services (Apache Axis) component of Oracle Secure Global Desktop can be exploited remotely to obtain sensitive information, bypass security restrictions, cause denial of service.
  3. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to cause denial of service.
  4. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information.
  5. Vulnerability in Core component of Oracle VM VirtualBox can be exploited remotely to obtain sensitive information, bypass security restrictions.
  6. Vulnerability in Core (Mojarra) component of Oracle Secure Global Desktop can be exploited remotely to obtain sensitive information, bypass security restrictions.
  7. Vulnerability in Web Server (Apache HTTPD Server) component of Oracle Secure Global Desktop can be exploited remotely to obtain sensitive information, bypass security restrictions.
  8. Vulnerability in Core(OpenSSL) component of Oracle VM VirtualBox can be exploited to bypass security restrictions;
Пораженные продукты

Oracle VirtualBox 5.2.x up to 5.2.36
Oracle VirtualBox 6.0.x up to 6.0.16
Oracle VirtualBox 6.1.x up to 6.1.2

Решение

Update to the latest version
Download Oracle Virtual Box

Первичный источник обнаружения
Oracle Critical Patch Update Advisory - January 2020
Оказываемое влияние
?
OSI 
[?]

DoS 
[?]

SB 
[?]
Связанные продукты
Oracle VirtualBox
CVE-IDS
CVE-2019-15470.0Unknown
CVE-2020-26740.0Unknown
CVE-2020-26820.0Unknown
CVE-2019-02270.0Unknown
CVE-2020-26980.0Unknown
CVE-2020-27010.0Unknown
CVE-2020-27020.0Unknown
CVE-2020-27260.0Unknown
CVE-2020-26810.0Unknown
CVE-2020-26890.0Unknown
CVE-2020-26900.0Unknown
CVE-2020-26910.0Unknown
CVE-2020-26920.0Unknown
CVE-2020-27030.0Unknown
CVE-2020-27040.0Unknown
CVE-2020-27050.0Unknown
CVE-2020-27250.0Unknown
CVE-2020-26780.0Unknown
CVE-2019-170910.0Unknown
CVE-2020-27270.0Unknown
CVE-2020-26930.0Unknown
CVE-2019-100920.0Unknown