CVE-2017-10209
published 2017-08-08CVE-2017-10209: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24…
PriorityP419medium5.2CVSS 3.0
AVLACLPRLUINSCCLINAL
EPSS
0.41%
33.5th percentile
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 5.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L).
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.1.24-dfsg-1 (sid) | virtualbox 5.1.24-dfsg-1 (sid) |
| libarchive | libarchive | >= 0 < 3.1.2-7ubuntu2.6 | 3.1.2-7ubuntu2.6 |
| libarchive | libarchive | >= 0 < 3.1.2-11ubuntu0.16.04.4 | 3.1.2-11ubuntu0.16.04.4 |
| libarchive | libarchive | >= 0 < 3.2.2-3.1ubuntu0.1 | 3.2.2-3.1ubuntu0.1 |
| oracle | vm_virtualbox | <= 5.1.22 | — |
| oracle_corporation | oracle_vm_virtualbox | >= unspecified < 5.1.24 | 5.1.24 |
| sun | virtualbox | >= 0 < 5.1.38-dfsg-0ubuntu1.16.04.1 | 5.1.38-dfsg-0ubuntu1.16.04.1 |
CVSS provenance
nvdv3.05.2MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:N/A:P
osv5.5MEDIUM
vendor_debian5.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-xq7f-qm87-m6wg: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
ghsa_unreviewed·2022-05-13
CVE-2017-10209 [MEDIUM] GHSA-xq7f-qm87-m6wg: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 5.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L).
OSV
libarchive vulnerabilities
osv·2018-08-13·CVSS 5.5
CVE-2016-10209 libarchive vulnerabilities
libarchive vulnerabilities
It was discovered that libarchive incorrectly handled certain archive files.
A remote attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2016-10209, CVE-2016-10349, CVE-2016-10350)
Agostino Sarubbo discovered that libarchive incorrectly handled certain XAR files.
A remote attacker could possibly use this issue to cause a denial of service.
This issue only affected Ubuntu 14.04 LTS and Ubuntu 16.04 LTS.
(CVE-2017-14166)
It was discovered that libarchive incorrectly handled certain files.
A remote attacker could possibly use this issue to get access to sensitive
information. (CVE-2017-14501, CVE-2017-14503)
OSV
CVE-2017-10209: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
osv·2017-08-08·CVSS 5.2
CVE-2017-10209 [MEDIUM] CVE-2017-10209: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 5.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L).
Debian
CVE-2017-10209: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
vendor_debian·2017·CVSS 5.2
CVE-2017-10209 [MEDIUM] CVE-2017-10209: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). The supported version that is affected is Prior to 5.1.24. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle VM VirtualBox accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle VM VirtualBox. CVSS 3.0 Base Score 5.2 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L).
Scope
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/99709http://www.securitytracker.com/id/1038929http://www.oracle.com/technetwork/security-advisory/cpujul2017-3236622.htmlhttp://www.securityfocus.com/bid/99709http://www.securitytracker.com/id/1038929
2017-08-08
Published