CVE-2018-2687
published 2018-01-18CVE-2018-2687: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and…
PriorityP338high8.6CVSS 3.0
AVLACLPRNUIRSCCHIHAH
EPSS
0.53%
41.3th percentile
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 5.2.6-dfsg-1 (sid) | virtualbox 5.2.6-dfsg-1 (sid) |
| oracle | vm_virtualbox | >= 5.1.0 < 5.1.32 | 5.1.32 |
| oracle | vm_virtualbox | >= 5.2.0 < 5.2.6 | 5.2.6 |
| oracle_corporation | vm_virtualbox | >= unspecified < 5.1.32 | 5.1.32 |
| oracle_corporation | vm_virtualbox | >= unspecified < 5.2.6 | 5.2.6 |
| sun | virtualbox | >= 0 < 6.1.16-dfsg-6~ubuntu1.20.04.1 | 6.1.16-dfsg-6~ubuntu1.20.04.1 |
CVSS provenance
nvdv3.08.6HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv8.6HIGH
vendor_debian8.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7pcq-f6pq-5cpf: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
ghsa_unreviewed·2022-05-13
CVE-2018-2687 [HIGH] GHSA-7pcq-f6pq-5cpf: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
OSV
CVE-2018-2687: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
osv·2018-01-18·CVSS 8.6
CVE-2018-2687 [HIGH] CVE-2018-2687: Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core)
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Debian
CVE-2018-2687: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
vendor_debian·2018·CVSS 8.6
CVE-2018-2687 [HIGH] CVE-2018-2687: virtualbox - Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (su...
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.1.32 and Prior to 5.2.6. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where Oracle VM VirtualBox executes to compromise Oracle VM VirtualBox. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle VM VirtualBox, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.0 Base Score 8.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H).
Scope: local
sid: resolved (fixe
No detection rules found.
No public exploits indexed.
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
## VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative 2018/08/29 Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library . Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it al
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
## VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative Aug 29, 2018 Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library . Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
# VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative
2018/08/29
Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library. Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it alm
Trendmicro
VirtualBox 3D Acceleration: An accelerated attack surface
blogs_trendmicro·2018-08-29·CVSS 8.2
[HIGH] VirtualBox 3D Acceleration: An accelerated attack surface
## VirtualBox 3D Acceleration: An accelerated attack surface
This post goes over VirtualBox 3D Acceleration, which is an accelerated attack surface.
By: Zero Day Initiative Aug 29, 2018 Read time: ( words)
Save to Folio
VirtualBox is a free hypervisor currently being developed and maintained by Oracle Corporation. While perhaps lesser known, it’s a direct competitor to VMware WorkStation and Microsoft Hyper-V. In July 2017, we started receiving vulnerabilities in VirtualBox 3D acceleration functionality, which is implemented with the Chromium library . Oracle warns in their documentation against enabling 3D Acceleration due to the security implications it imposes and the attack surface it exposes. What few know is that the code behind 3D Acceleration is very old. And by old, I mean it
Bugzilla
CVE-2018-11762 tika: Zip Slip vulnerability in tika-app
bugzilla·2018-09-24·CVSS 5.9
CVE-2018-11762 [MEDIUM] CVE-2018-11762 tika: Zip Slip vulnerability in tika-app
CVE-2018-11762 tika: Zip Slip vulnerability in tika-app
A flaw was found in Apache Tika 0.9 to 1.18, in a rare edge case where a user does not specify an extract directory on the commandline (--extract-dir=) and the input file has an embedded file with an absolute path, such as "C:/evil.bat", tika-app would overwrite that file.
References:
https://lists.apache.org/thread.html/ab2e1af38975f5fc462ba89b517971ef892ec3d06bee12ea2258895b@%3Cdev.tika.apache.org%3E
https://seclists.org/oss-sec/2018/q3/256
Discussion:
Created tika tracking bugs for this issue:
Affects: fedora-all [bug 1632470]
---
Upstream bug:
https://issues.apache.org/jira/browse/TIKA-2687
Upstream commits:
https://github.com/apache/tika/commit/a09d853dbed712f644e274b497cce254f3189d57
https://github.com/apache/tika/com
http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102691http://www.securitytracker.com/id/1040202http://www.oracle.com/technetwork/security-advisory/cpujan2018-3236628.htmlhttp://www.securityfocus.com/bid/102691http://www.securitytracker.com/id/1040202
2018-01-18
Published