{
  "schema_version": "1.7.0",
  "id": "MGASA-2024-0275",
  "published": "2024-07-29T18:26:26Z",
  "modified": "2024-07-29T17:59:33Z",
  "summary": "Updated virtualbox & kmod-virtualbox packages fix security vulnerabilities",
  "details": "Easily exploitable vulnerability allows high privileged attacker with\nlogon to the infrastructure where Oracle VM VirtualBox executes to\ncompromise Oracle VM VirtualBox. While the vulnerability is in Oracle VM\nVirtualBox, attacks may significantly impact additional products (scope\nchange). Successful attacks of this vulnerability can result in takeover\nof Oracle VM VirtualBox. CVSS 3.1 Base Score 8.2 (Confidentiality,\nIntegrity and Availability impacts). CVSS Vector:\n(CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).\n",
  "upstream": [
    "CVE-2024-21141",
    "CVE-2024-21161",
    "CVE-2024-21164"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2024-0275.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=33408"
    },
    {
      "type": "WEB",
      "url": "https://www.oracle.com/security-alerts/cpujul2024.html#AppendixOVIR"
    },
    {
      "type": "WEB",
      "url": "https://www.virtualbox.org/wiki/Changelog-7.0#v20"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "virtualbox",
        "purl": "pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.20-1.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:9",
        "name": "kmod-virtualbox",
        "purl": "pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-9"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "7.0.20-51.mga9"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
