Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.853790
Category:SuSE Local Security Checks
Title:openSUSE: Security Advisory for virtualbox (openSUSE-SU-2021:0630-1)
Summary:The remote host is missing an update for the 'virtualbox'; package(s) announced via the openSUSE-SU-2021:0630-1 advisory.
Description:Summary:
The remote host is missing an update for the 'virtualbox'
package(s) announced via the openSUSE-SU-2021:0630-1 advisory.

Vulnerability Insight:
This update for virtualbox fixes the following issues:

- Version bump to 6.1.20 (released April 20 2021 by Oracle) Fixes
boo#1183329 'virtualbox 6.1.18 crashes when it runs nested VM' Fixes
boo#1183125 'Leap 15.3 installation in Virtualbox without VBox
integration' Fixes CVE-2021-2264 and boo#1184542. The directory for the
user .start files for autostarting VMs is moved from /etc/vbox to
/etc/vbox/autostart.d. In addition, the autostart service is hardened
(by Oracle).

- change the modalias for guest-tools and guest-x11 to get them to
autoinstall.

- Own %{_sysconfdir}/X11/xinit/xinitrc.d as default packages (eg systemd)
no longer do so, breaking package build.

- Update fixes_for_leap15.3 for kernel API changes between 5.3.18-45 and
5.3.18-47.

- Add code to generate guest modules for Leap 15.2 and Leap 15.3. The
kernel versions do not allow window resizing. Files
'virtualbox-kmp-files-leap' and 'vboxguestconfig.sh' are added

- Fixes CVE-2021-2074, boo#1181197 and CVE-2021-2129, boo#1181198.

- Under some circumstances, shared folders are mounted as root.

Affected Software/OS:
'virtualbox' package(s) on openSUSE Leap 15.2.

Solution:
Please install the updated package(s).

CVSS Score:
4.6

CVSS Vector:
AV:L/AC:L/Au:N/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-2074
https://security.gentoo.org/glsa/202101-15
https://www.oracle.com/security-alerts/cpujan2021.html
Common Vulnerability Exposure (CVE) ID: CVE-2021-2129
Common Vulnerability Exposure (CVE) ID: CVE-2021-2264
https://security.gentoo.org/glsa/202208-36
https://www.oracle.com/security-alerts/cpuapr2021.html
http://www.openwall.com/lists/oss-security/2021/04/26/1
http://www.openwall.com/lists/oss-security/2021/04/26/2
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.