~ubuntu-security/ubuntu-cve-tracker/master

« back to all changes in this revision

Viewing changes to active/CVE-2018-2686

  • Committer: Steve Beattie
  • Date: 2019-02-19 06:18:27 UTC
  • Revision ID: sbeattie@ubuntu.com-20190219061827-oh57fzcfc1u9dlfk
The ubuntu-cve-tracker project has been converted to git.

Please use 'git clone https://git.launchpad.net/ubuntu-cve-tracker' to
get the converted tree.

Show diffs side-by-side

added added

removed removed

Lines of Context:
1
 
Candidate: CVE-2018-2686
2
 
PublicDate: 2018-01-17
3
 
References:
4
 
 https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-2686
5
 
Description:
6
 
 Vulnerability in the Oracle VM VirtualBox component of Oracle
7
 
 Virtualization (subcomponent: Core). Supported versions that are affected
8
 
 are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability
9
 
 allows unauthenticated attacker with logon to the infrastructure where
10
 
 Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox.
11
 
 Successful attacks require human interaction from a person other than the
12
 
 attacker and while the vulnerability is in Oracle VM VirtualBox, attacks
13
 
 may significantly impact additional products. Successful attacks of this
14
 
 vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base
15
 
 Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS
16
 
 Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
17
 
Ubuntu-Description:
18
 
Notes:
19
 
Bugs:
20
 
Priority: medium
21
 
Discovered-by:
22
 
Assigned-to:
23
 
 
24
 
 
25
 
Patches_virtualbox:
26
 
upstream_virtualbox: released (5.2.6-dfsg-1)
27
 
precise/esm_virtualbox: DNE
28
 
trusty_virtualbox: needs-triage
29
 
xenial_virtualbox: needs-triage
30
 
artful_virtualbox: needs-triage
31
 
bionic_virtualbox: needs-triage
32
 
devel_virtualbox: needs-triage