Author Topic: Avast NG Vurnable? Oracle Virtualbox CVE-2015-0377  (Read 2319 times)

0 Members and 1 Guest are viewing this topic.

Offline [Oli]

  • Sr. Member
  • ****
  • Posts: 333
Avast NG Vurnable? Oracle Virtualbox CVE-2015-0377
« on: January 27, 2015, 07:57:21 PM »
Hi Avast, I would like to provide a small warning about Avast NG's depedency (Virtualbox.)

The CVE is: CVE-2015-0377

I have been monitoring the NVD for the week and noticed that there is a CVE for Oracle Virtualbox (The system embedded into Avast NG.)

There has been an emergency update from Oracle. The exploit details can be found at: https://www.us-cert.gov/ncas/bulletins/SB15-026

The Patch information can be found at http://www.oracle.com/technetwork/topics/security/cpujan2015-1972971.html

I couldn't find a direct email to send this message to anyone. I thought this might be the best place to warn you.

Thanks
Oliver

Offline bob3160

  • Avast √úberevangelist
  • Probably Bot
  • *****
  • Posts: 45657
  • 61 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast NG Vurnable? Oracle Virtualbox CVE-2015-0377
« Reply #1 on: January 27, 2015, 08:01:17 PM »
Moderator  notified. :)
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v21H2 64bit, 16 Gig Ram, 1TB SSD, AvastOmni 21.6, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline Spec8472

  • Avast team
  • Sr. Member
  • *
  • Posts: 244
Re: Avast NG Vurnable? Oracle Virtualbox CVE-2015-0377
« Reply #2 on: January 27, 2015, 10:33:56 PM »
Thanks for report, CVE-2015-0377 affects only VBox up to version 4.2.28. Avast 2015 is using VBox 4.3.16.

Hi Avast, I would like to provide a small warning about Avast NG's depedency (Virtualbox.)

The CVE is: CVE-2015-0377

I have been monitoring the NVD for the week and noticed that there is a CVE for Oracle Virtualbox (The system embedded into Avast NG.)

There has been an emergency update from Oracle. The exploit details can be found at:

The Patch information can be found at

I couldn't find a direct email to send this message to anyone. I thought this might be the best place to warn you.

Thanks
Oliver

Offline bob3160

  • Avast √úberevangelist
  • Probably Bot
  • *****
  • Posts: 45657
  • 61 Years of Happiness
    • bob3160 Protecting Yourself, Your Computer and, Your Identity
Re: Avast NG Vurnable? Oracle Virtualbox CVE-2015-0377
« Reply #3 on: January 28, 2015, 03:25:15 PM »
@Spec8472,
Thanks for the info and reassurance that we are safe. :)
Free avast! Security Seminar: http://bit.ly/2N1eaR2  -  Important: http://www.organdonor.gov/ -- My Web Site: http://bob3160.strikingly.com/ - Win 11 Pro v21H2 64bit, 16 Gig Ram, 1TB SSD, AvastOmni 21.6, How to Successfully Install Avast http://goo.gl/VLXdeRepair & Clean Install https://goo.gl/t7aJGq

Offline [Oli]

  • Sr. Member
  • ****
  • Posts: 333
Re: Avast NG Vurnable? Oracle Virtualbox CVE-2015-0377
« Reply #4 on: January 28, 2015, 06:12:52 PM »
Thanks for report, CVE-2015-0377 affects only VBox up to version 4.2.28. Avast 2015 is using VBox 4.3.16.

Hi Avast, I would like to provide a small warning about Avast NG's depedency (Virtualbox.)

The CVE is: CVE-2015-0377

I have been monitoring the NVD for the week and noticed that there is a CVE for Oracle Virtualbox (The system embedded into Avast NG.)

There has been an emergency update from Oracle. The exploit details can be found at:

The Patch information can be found at

I couldn't find a direct email to send this message to anyone. I thought this might be the best place to warn you.

Thanks
Oliver

Thanks for clarifying, Glad we are not affected!