Vulnerability CVE-2019-2552: Information

Description

Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are prior to 5.2.24 and prior to 6.0.2. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Severity: HIGH (8.8) Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Published: Jan. 16, 2019
Modified: Aug. 24, 2020

Fixed packages

Package name
Branch
Fixed in version
Version from repository
Errata ID
Task #
State
kernel-modules-virtualbox-addition-std-defsisyphus5.2.24-alt1.265824.17.0.14-alt1.393561.1ALT-PU-2019-1135-1219496Fixed
kernel-modules-virtualbox-addition-std-defp105.2.24-alt1.265824.16.1.50-alt1.330453.1ALT-PU-2019-1135-1219496Fixed
kernel-modules-virtualbox-addition-std-defp95.2.24-alt1.265824.16.1.26-alt1.328978.1ALT-PU-2019-1135-1219496Fixed
kernel-modules-virtualbox-addition-std-defp85.2.26-alt1.264603.0.M80P.15.2.42-alt1.264785.0.M80P.1ALT-PU-2019-1281-1221021Fixed
kernel-modules-virtualbox-addition-std-defc9f25.2.24-alt1.265824.16.1.46-alt1.330454.0.c9f.2ALT-PU-2019-1135-1219496Fixed
kernel-modules-virtualbox-addition-un-defsisyphus5.2.24-alt1.267026.17.0.14-alt1.394781.1ALT-PU-2019-1137-1219496Fixed
kernel-modules-virtualbox-addition-un-defp105.2.24-alt1.267026.16.1.50-alt1.393557.1ALT-PU-2019-1137-1219496Fixed
kernel-modules-virtualbox-addition-un-defp95.2.24-alt1.267026.16.1.26-alt1.330455.1ALT-PU-2019-1137-1219496Fixed
kernel-modules-virtualbox-addition-un-defp85.2.26-alt1.267024.0.M80P.15.2.42-alt1.267318.0.M80P.1ALT-PU-2019-1280-1221021Fixed
kernel-modules-virtualbox-addition-un-defc10f15.2.24-alt1.267026.16.1.46-alt1.393557.0.c10f.1ALT-PU-2019-1137-1219496Fixed
kernel-modules-virtualbox-addition-un-defc9f25.2.24-alt1.267026.16.1.46-alt1.330269.2ALT-PU-2019-1137-1219496Fixed
kernel-modules-virtualbox-std-defsisyphus5.2.24-alt1.265824.17.0.14-alt1.393561.1ALT-PU-2019-1134-1219496Fixed
kernel-modules-virtualbox-std-defp105.2.24-alt1.265824.16.1.50-alt1.330453.1ALT-PU-2019-1134-1219496Fixed
kernel-modules-virtualbox-std-defp95.2.24-alt1.265824.16.1.26-alt1.328978.1ALT-PU-2019-1134-1219496Fixed
kernel-modules-virtualbox-std-defp85.2.26-alt1.264603.0.M80P.15.2.42-alt1.264785.0.M80P.1ALT-PU-2019-1278-1221021Fixed
kernel-modules-virtualbox-std-defc9f25.2.24-alt1.265824.16.1.46-alt1.330454.0.c9f.2ALT-PU-2019-1134-1219496Fixed
kernel-modules-virtualbox-un-defsisyphus5.2.24-alt1.267026.17.0.14-alt1.394781.1ALT-PU-2019-1136-1219496Fixed
kernel-modules-virtualbox-un-defp105.2.24-alt1.267026.16.1.50-alt1.393557.1ALT-PU-2019-1136-1219496Fixed
kernel-modules-virtualbox-un-defp95.2.24-alt1.267026.16.1.26-alt1.330455.1ALT-PU-2019-1136-1219496Fixed
kernel-modules-virtualbox-un-defp85.2.26-alt1.267024.0.M80P.15.2.42-alt1.267318.0.M80P.1ALT-PU-2019-1279-1221021Fixed
kernel-modules-virtualbox-un-defc10f15.2.24-alt1.267026.16.1.46-alt1.393557.0.c10f.1ALT-PU-2019-1136-1219496Fixed
kernel-modules-virtualbox-un-defc9f25.2.24-alt1.267026.16.1.46-alt1.330269.2ALT-PU-2019-1136-1219496Fixed
virtualboxsisyphus5.2.24-alt37.0.14-alt2ALT-PU-2019-1133-1219496Fixed
virtualboxp105.2.24-alt36.1.50-alt1ALT-PU-2019-1133-1219496Fixed
virtualboxp95.2.24-alt36.1.26-alt1ALT-PU-2019-1133-1219496Fixed
virtualboxp85.2.26-alt15.2.42-alt2ALT-PU-2019-1277-1221021Fixed
virtualboxc10f15.2.24-alt36.1.46-alt1ALT-PU-2019-1133-1219496Fixed
virtualboxc9f25.2.24-alt36.1.46-alt1ALT-PU-2019-1133-1219496Fixed

References to Advisories, Solutions, and Tools

    1. Configuration 1

      cpe:2.3:a:oracle:vm_virtualbox:6.0.0:*:*:*:*:*:*:*

      cpe:2.3:a:oracle:vm_virtualbox:*:*:*:*:*:*:*:*
      End excliding
      5.2.24