[Bug 1203370] New: AUDIT-FIND: virtualbox: insecure permissions on /dev/vboxuser
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 Bug ID: 1203370 Summary: AUDIT-FIND: virtualbox: insecure permissions on /dev/vboxuser Classification: openSUSE Product: openSUSE Tumbleweed Version: Current Hardware: Other OS: Other Status: NEW Severity: Normal Priority: P5 - None Component: Security Assignee: security-team@suse.de Reporter: wolfgang.frisch@suse.com QA Contact: qa-bugs@suse.de Found By: --- Blocker: --- The udev rule for VirtualBox guests sets the permissions of /dev/vboxuser to 0666. This device node is used for guest-host communication, and while there is no known attack vector at the moment, it has been subject to security vulnerabilities in the past: CVE-2018-3055 and CVE-2018-3085 [2]. In my opinion it would be prudent to change it back to 0660 and set the group to `vboxguest`. [1] https://build.opensuse.org/request/show/994651 [2] https://github.com/niklasb/3dpwn -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 Wolfgang Frisch <wolfgang.frisch@suse.com> changed: What |Removed |Added ---------------------------------------------------------------------------- Assignee|security-team@suse.de |Larry.Finger@gmail.com QA Contact|qa-bugs@suse.de |security-team@suse.de -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c1 --- Comment #1 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1203370) was mentioned in https://build.opensuse.org/request/show/1004161 15.3 / virtualbox -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c2 --- Comment #2 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1203370) was mentioned in https://build.opensuse.org/request/show/1004167 15.4 / virtualbox -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c5 --- Comment #5 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1203370) was mentioned in https://build.opensuse.org/request/show/1006483 15.4 / virtualbox -- You are receiving this mail because: You are on the CC list for the bug.
http://bugzilla.opensuse.org/show_bug.cgi?id=1203370 http://bugzilla.opensuse.org/show_bug.cgi?id=1203370#c6 --- Comment #6 from OBSbugzilla Bot <bwiedemann+obsbugzillabot@suse.com> --- This is an autogenerated message for OBS integration: This bug (1203370) was mentioned in https://build.opensuse.org/request/show/1008292 15.4 / virtualbox -- You are receiving this mail because: You are on the CC list for the bug.
participants (1)
-
bugzilla_noreply@suse.com