Debian Security Advisory

DSA-2878-1 virtualbox -- security update

Date Reported:
13 Mar 2014
Affected Packages:
virtualbox
Vulnerable:
Yes
Security database references:
In the Debian bugtracking system: Bug 735410.
In Mitre's CVE dictionary: CVE-2013-5892, CVE-2014-0404, CVE-2014-0406, CVE-2014-0407.
More information:

Matthew Daley discovered multiple vulnerabilities in VirtualBox, a x86 virtualisation solution, resulting in denial of service, privilege escalation and an information leak.

For the oldstable distribution (squeeze), these problems have been fixed in version 3.2.10-dfsg-1+squeeze2 of the virtualbox-ose source package.

For the stable distribution (wheezy), these problems have been fixed in version 4.1.18-dfsg-2+deb7u2.

For the testing distribution (jessie), these problems have been fixed in version 4.3.6-dfsg-1.

For the unstable distribution (sid), these problems have been fixed in version 4.3.6-dfsg-1.

We recommend that you upgrade your virtualbox packages.