PT-2015-2482 · Oracle+1 · Virtualbox+1

Published

2015-10-21

·

Updated

2024-06-15

·

CVE-2015-4896

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle VM VirtualBox versions prior to 4.0.34 Oracle VM VirtualBox versions prior to 4.1.42 Oracle VM VirtualBox versions prior to 4.2.34 Oracle VM VirtualBox versions prior to 4.3.32 Oracle VM VirtualBox versions prior to 5.0.8
Description The issue is related to errors in the code of Oracle VM VirtualBox, which can be exploited by a remote attacker to cause a denial of service when the Remote Display feature (RDP) is enabled. The exact vectors related to the Core component are unknown.
Recommendations For versions prior to 4.0.34, update to version 4.0.34 or later. For versions prior to 4.1.42, update to version 4.1.42 or later. For versions prior to 4.2.34, update to version 4.2.34 or later. For versions prior to 4.3.32, update to version 4.3.32 or later. For versions prior to 5.0.8, update to version 5.0.8 or later. As a temporary workaround, consider disabling the Remote Display feature (RDP) until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-1230
ALT-PU-2016-1231
ALT-PU-2016-1232
ALT-PU-2016-1256
ALT-PU-2016-1263
BDU:2015-11847
CVE-2015-4896
DSA-3384-1
MGASA-2015-0415
OPENSUSE-SU-2024:10020-1

Affected Products

Alt Linux
Virtualbox