{
  "schema_version": "1.7.0",
  "id": "MGASA-2023-0239",
  "published": "2023-07-23T21:59:03Z",
  "modified": "2023-07-23T20:34:24Z",
  "summary": "Updated virtualbox packages fix security vulnerabilities",
  "details": "This update provides the upstream 7.0.10 maintenance release that\nfixes at least the following security vulnerabilities:\n\nVulnerability in the Oracle VM VirtualBox prior to 7.0.10 contains an\neasily exploitable vulnerability that allows high privileged attacker\nwith logon to the infrastructure where Oracle VM VirtualBox executes\nto compromise Oracle VM VirtualBox. Successful attacks require human\ninteraction from a person other than the attacker. Successful attacks\nof this vulnerability can result in unauthorized ability to cause a\nhang or frequently repeatable crash (complete DOS) of Oracle VM\nVirtualBox (CVE-2023-22016).\n\nVulnerability in Oracle VM VirtualBox prior to 7.0.10 contains a difficult\nto exploit vulnerability allows an unauthenticated attacker with network\naccess via RDP to compromise Oracle VM VirtualBox. Successful attacks of\nthis vulnerability can result in takeover of Oracle VM VirtualBox \n(CVE-2023-22018).\n\nFor other fixes in  this update, see the referenced changelog.\n",
  "upstream": [
    "CVE-2023-22016",
    "CVE-2023-22018"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2023-0239.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=32124"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujul2023.html#AppendixOVIR"
    },
    {
      "type": "WEB",
      "url": "https://www.virtualbox.org/wiki/Changelog-7.0#v10"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "virtualbox",
        "purl": "pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "kmod-virtualbox",
        "purl": "pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.10-1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
