MGASA-2015-0228

Source
https://advisories.mageia.org/MGASA-2015-0228.html
Import Source
https://advisories.mageia.org/MGASA-2015-0228.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2015-0228
Related
Published
2015-05-15T18:23:49Z
Modified
2015-05-15T18:14:00Z
Summary
Updated virtualbox packages fix security vulnerabilities
Details

Updated virtualbox packages fixes security vulnerability

This update provides the 4.3.28 maintenance release fixing the following security issue:

The Floppy Disk Controller (FDC) in QEMU, XEN, KVM and virtualbox allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arbitrary code via the FDCMDREADID, FDCMDDRIVESPECIFICATION_COMMAND, or other unspecified commands, aka VENOM (CVE-2015-3456).

For other fixes in the maintenance release, read the referenced changelog.

References
Credits

Affected packages

Mageia:4 / kmod-vboxadditions

Package

Name
kmod-vboxadditions
Purl
pkg:rpm/mageia/kmod-vboxadditions?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.28-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.28-1.mga4

Ecosystem specific

{
    "section": "core"
}

Mageia:4 / virtualbox

Package

Name
virtualbox
Purl
pkg:rpm/mageia/virtualbox?distro=mageia-4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.3.28-1.mga4

Ecosystem specific

{
    "section": "core"
}