Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 289307 - app-emulation/virtualbox-ose-3.0.6*: Security Vulnerability in the VBoxNetAdpCtl Configuration Tool (CVE-2009-3704, CVE-2009-3692)
Summary: app-emulation/virtualbox-ose-3.0.6*: Security Vulnerability in the VBoxNetAdp...
Status: RESOLVED DUPLICATE of bug 288836
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Vulnerabilities (show other bugs)
Hardware: All Linux
: High normal (vote)
Assignee: Gentoo Security
URL: http://sunsolve.sun.com/search/docume...
Whiteboard: B2 [stable]
Keywords:
Depends on:
Blocks:
 
Reported: 2009-10-16 12:40 UTC by Martin Alexander Neumann
Modified: 2020-04-10 11:36 UTC (History)
3 users (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Martin Alexander Neumann 2009-10-16 12:40:49 UTC
A security vulnerability in the VBoxNetAdpCtl configuration tool for certain
Sun VirtualBox 3.0 packages may allow local unprivileged users who are
authorized to run VirtualBox to execute arbitrary commands with root
privileges.

There are no predictable symptoms to indicate this issue has been exploited to
gain elevated privileges.

This issue is addressed in the following release: Sun VirtualBox 3.0.8 (for all
platforms)

Reproducible: Didn't try
Comment 1 Christian Faulhammer (RETIRED) gentoo-dev 2009-10-18 09:26:06 UTC
From bug 288836

> (In reply to comment #4)
>> >>> Install virtualbox-ose-3.0.8 into /var/tmp/portage/app-emulation/virtualbox-ose-3.0.8/image/ category app-emulation
>> install: cannot stat `vboxwebsrv': No such file or directory
>> !!! doins: vboxwebsrv does not exist
>> 
>> USE=vboxwebsrv fails.
> hi, which version of net-libs/gsoap are you using?

 The current stable 2.7.9f 

Please bring the updated ebuild into Portage and file a stabilisation request for gsoap (will be off in a minute).
Comment 2 Alessio Cassibba (X-Drum) 2009-10-18 18:18:37 UTC
(In reply to comment #1)
>  The current stable 2.7.9f 
> 
> Please bring the updated ebuild into Portage and file a stabilisation request
> for gsoap (will be off in a minute).
> 

Adding Patrick in CC since i cannot commit to the portage tree,
( can you please do it for me? ), the updated virtualbox-ose-3.0.8-r1 ebuild is located on jokey's overlay[1].

Filed the stabilization request for net-libs/gsoap-2.7.13 bug #289618

[1] http://overlays.gentoo.org/dev/jokey/browser/trunk/app-emulation/virtualbox-ose
Comment 3 Christian Faulhammer (RETIRED) gentoo-dev 2009-10-18 23:03:33 UTC

*** This bug has been marked as a duplicate of bug 288836 ***