Bug 1198678 - (CVE-2022-21487) VUL-1: CVE-2022-21487: virtualbox: Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox
(CVE-2022-21487)
VUL-1: CVE-2022-21487: virtualbox: Easily exploitable vulnerability allows hi...
Status: RESOLVED FIXED
Classification: openSUSE
Product: openSUSE Distribution
Classification: openSUSE
Component: Basesystem
Leap 15.3
Other Other
: P4 - Low : Minor (vote)
: ---
Assigned To: Larry Finger
Security Team bot
https://smash.suse.de/issue/329593/
:
Depends on:
Blocks:
  Show dependency treegraph
 
Reported: 2022-04-20 07:42 UTC by Alexander Bergmann
Modified: 2022-06-23 00:40 UTC (History)
0 users

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2022-04-20 07:42:14 UTC
CVE-2022-21487

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization
(component: Core). The supported version that is affected is Prior to 6.1.34.
Easily exploitable vulnerability allows low privileged attacker with logon to
the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM
VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may
significantly impact additional products (scope change). Successful attacks of
this vulnerability can result in unauthorized read access to a subset of Oracle
VM VirtualBox accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality
impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-21487
https://www.oracle.com/security-alerts/cpuapr2022.html#CVE-2022-21487
https://www.oracle.com/security-alerts/cpuapr2022.html
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-21487
Comment 1 OBSbugzilla Bot 2022-05-05 22:40:07 UTC
This is an autogenerated message for OBS integration:
This bug (1198678) was mentioned in
https://build.opensuse.org/request/show/975266 15.3 / virtualbox
Comment 2 Larry Finger 2022-05-06 01:30:29 UTC
VB version 6.1.34 fixes this issue and has been submitted to TW, Leap 15.4, Leap 15.3, and Leap 15.2,
Comment 3 OBSbugzilla Bot 2022-05-06 02:40:12 UTC
This is an autogenerated message for OBS integration:
This bug (1198678) was mentioned in
https://build.opensuse.org/request/show/975277 15.2 / virtualbox
Comment 4 Swamp Workflow Management 2022-05-18 13:19:12 UTC
openSUSE-SU-2022:0135-1: An update that fixes 32 vulnerabilities is now available.

Category: security (important)
Bug References: 1064976,1064978,1069412,1099260,1099263,1102912,1121426,1121428,1184522,1192869,1198676,1198677,1198678,1198679,1198680,1198703,951562,970662,970663,991940
CVE References: CVE-2011-5325,CVE-2015-9261,CVE-2016-2147,CVE-2016-2148,CVE-2016-6301,CVE-2017-15873,CVE-2017-15874,CVE-2017-16544,CVE-2018-1000500,CVE-2018-1000517,CVE-2018-20679,CVE-2019-5747,CVE-2021-28831,CVE-2021-42373,CVE-2021-42374,CVE-2021-42375,CVE-2021-42376,CVE-2021-42377,CVE-2021-42378,CVE-2021-42379,CVE-2021-42380,CVE-2021-42381,CVE-2021-42382,CVE-2021-42383,CVE-2021-42384,CVE-2021-42385,CVE-2021-42386,CVE-2022-21465,CVE-2022-21471,CVE-2022-21487,CVE-2022-21488,CVE-2022-21491
JIRA References: 
Sources used:
openSUSE Leap 15.3 (src):    busybox-1.34.1-4.9.1, virtualbox-6.1.34-lp153.2.27.2, virtualbox-kmp-6.1.34-lp153.2.27.1
Comment 5 OBSbugzilla Bot 2022-06-09 06:40:06 UTC
This is an autogenerated message for OBS integration:
This bug (1198678) was mentioned in
https://build.opensuse.org/request/show/981407 15.4 / virtualbox
Comment 6 OBSbugzilla Bot 2022-06-23 00:40:05 UTC
This is an autogenerated message for OBS integration:
This bug (1198678) was mentioned in
https://build.opensuse.org/request/show/984619 15.4 / virtualbox