Bug ID 1231738
Summary VUL-0: CVE-2024-21263: core: Oracle VM VirtualBox can be made to crash or provide unauthorized read access to certain data by a low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.6
Hardware Other
URL https://smash.suse.de/issue/424160/
OS Other
Status NEW
Severity Normal
Priority P5 - None
Component Security
Assignee jengelh@inai.de
Reporter smash_bz@suse.de
QA Contact security-team@suse.de
CC camila.matos@suse.com
Target Milestone ---
Found By Security Response Team
Blocker ---

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core).  Supported versions that are affected are Prior to 7.0.22
and  prior to 7.1.2. Easily exploitable vulnerability allows low privileged
attacker with logon to the infrastructure where Oracle VM VirtualBox executes
to compromise Oracle VM VirtualBox.  Successful attacks of this vulnerability
can result in unauthorized ability to cause a hang or frequently repeatable
crash (complete DOS) of Oracle VM VirtualBox and  unauthorized read access to a
subset of Oracle VM VirtualBox accessible data. CVSS 3.1 Base Score 6.1
(Confidentiality and Availability impacts).  CVSS Vector:
(CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H).

References:
https://www.oracle.com/security-alerts/cpuoct2024.html
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2024-21263
https://www.cve.org/CVERecord?id=CVE-2024-21263
https://bugzilla.redhat.com/show_bug.cgi?id=2318920


You are receiving this mail because: