Bug ID 1201720
Summary VUL-0: CVE-2022-21571,CVE-2022-21554: Vulnerability in the Oracle VM VirtualBox (component: Core) affecting version prior to 6.1.36
Classification openSUSE
Product openSUSE Distribution
Version Leap 15.4
Hardware Other
URL https://smash.suse.de/issue/337709/
OS Other
Status NEW
Severity Major
Priority P5 - None
Component Virtualization:Other
Assignee Larry.Finger@gmail.com
Reporter gianluca.gabrielli@suse.com
QA Contact security-team@suse.de
Found By Security Response Team
Blocker ---

Vulnerabilities in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core). The supported version that is affected is Prior to 6.1.36.
Easily exploitable vulnerability allows high privileged attacker with logon to
the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM
VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may
significantly impact additional products (scope change). Successful attacks of
this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1
Base
Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector:
(CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21571
https://www.oracle.com/security-alerts/cpujul2022.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21571https://www.oracle.com/security-alerts/cpujul2022.html


You are receiving this mail because: