PT-2021-20965 · Oracle+2 · Virtualbox+2

Jie Liang

+2

·

Published

2021-10-20

·

Updated

2023-08-07

·

CVE-2021-35545

CVSS v3.1

6.7

Medium

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:H
Name of the Vulnerable Software and Affected Versions: Oracle VM VirtualBox versions prior to 6.1.28
Description: The issue allows a high privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of Oracle VM VirtualBox and unauthorized read access to a subset of Oracle VM VirtualBox accessible data. While the issue is in Oracle VM VirtualBox, attacks may significantly impact additional products.
Recommendations: For versions prior to 6.1.28, update to version 6.1.28 or later to resolve the issue. As a temporary workaround, consider restricting access to the Oracle VM VirtualBox infrastructure to minimize the risk of exploitation.

Fix

Related Identifiers

ALT-PU-2021-3169
ALT-PU-2021-3170
ALT-PU-2021-3171
ALT-PU-2021-3172
ALT-PU-2021-3173
ALT-PU-2021-3661
ALT-PU-2021-3662
ALT-PU-2021-3663
ALT-PU-2021-3664
ALT-PU-2021-3665
ALT-PU-2023-4088
ALT-PU-2023-4089
ALT-PU-2023-4090
ALT-PU-2023-4664
ALT-PU-2023-4665
ALT-PU-2023-4729
ALT-PU-2023-4730
CVE-2021-35545
MGASA-2021-0488
OPENSUSE-SU-2021:1393-1
OPENSUSE-SU-2021:1403-1
OPENSUSE-SU-2021_1393-1
OPENSUSE-SU-2021_1403-1

Affected Products

Alt Linux
Virtualbox
Suse