Risk | Low |
Patch available | YES |
Number of vulnerabilities | 10 |
CVE-ID | CVE-2018-2830 CVE-2018-2831 CVE-2018-2835 CVE-2018-2836 CVE-2018-2837 CVE-2018-2842 CVE-2018-2843 CVE-2018-2844 CVE-2018-2845 CVE-2018-2860 |
CWE-ID | CWE-264 CWE-200 |
Exploitation vector | Local |
Public exploit | Public exploit code for vulnerability #8 is available. |
Vulnerable software |
Gentoo Linux Operating systems & Components / Operating system |
Vendor | Gentoo |
Security Bulletin
This security bulletin contains information about 10 vulnerabilities.
EUVDB-ID: #VU11893
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2830
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11895
Risk: Low
CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2831
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to obtain potentially sensitive information on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper information control. A local attacker can gain access to potentially sensitive information.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11896
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2835
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11897
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2836
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11898
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2837
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11899
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2842
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11900
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2843
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11901
Risk: Low
CVSSv4.0: 7.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear]
CVE-ID: CVE-2018-2844
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: Yes
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.
EUVDB-ID: #VU11902
Risk: Low
CVSSv4.0: 4.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2845
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to obtain potentially sensitive information, write arbitrary files and cause DoS condition on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper information control. A local attacker can partially access data, partially modify data and cause the service to crash.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU11903
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2018-2860
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local attacker to gain elevated privileges on the target system.
The weakness exists in the Oracle VM VirtualBox Core component due to improper security restrictions. A local attacker can gain root privileges.
Update the affected packages.
app-emulation/virtualbox to version: 5.1.36
app-emulation/virtualbox-bin to version: 5.1.36.122089
Gentoo Linux: All versions
CPE2.3 External linkshttps://security.gentoo.org/glsa/201805-08
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.