Get the LinuxSecurity news you want faster with RSS
Powered By
Pardus: Virtualbox: Privilege escalation
Posted by Benjamin D. Thomas
A vulnerability has been reported in Sun xVM VirtualBox, which can be exploited by malicious, local users to gain escalated privileges.
------------------------------------------------------------------------
Pardus Linux Security Advisory 2009-49 security@pardus.org.tr
------------------------------------------------------------------------
Date: 2009-04-01
Severity: 2
Type: Local
------------------------------------------------------------------------
Summary
=======
A vulnerability has been reported in Sun xVM VirtualBox, which can be
exploited by malicious, local users to gain escalated privileges.
Description
===========
The vulnerability is caused due to an unspecified error in an
unspecified package, which can be exploited to execute arbitrary
commands with root privileges.
Successful exploitation requires permission to run VirtualBox.
Affected packages:
Pardus 2008:
virtualbox, all before 2.1.4-31-11
virtualbox-guest-utils, all before 2.1.4-31-5
virtualbox-modules, all before 2.1.4-3-3
Resolution
==========
There are update(s) for virtualbox, virtualbox-guest-utils,
virtualbox-modules. You can update them via Package Manager or with a
single command from console:
pisi up virtualbox virtualbox-guest-utils virtualbox-modules
References
==========
* http://bugs.pardus.org.tr/show_bug.cgi?id=9458
* http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0876