A Incorrect Default Permissions vulnerability in the packaging of virtualbox of openSUSE Factory allows local attackers in the vboxusers groupu to escalate to root. This issue affects: openSUSE Factory virtualbox version 6.1.20-1.1 and prior versions.
During installation, installed file permissions are set to allow anyone to modify those files.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Factory | Opensuse | * | 6.1.20-1.1 (including) |
Virtualbox | Ubuntu | bionic | * |
Virtualbox | Ubuntu | groovy | * |
Virtualbox | Ubuntu | hirsute | * |
Virtualbox | Ubuntu | impish | * |
Virtualbox | Ubuntu | kinetic | * |
Virtualbox | Ubuntu | lunar | * |
Virtualbox | Ubuntu | mantic | * |
Virtualbox | Ubuntu | trusty | * |
Virtualbox | Ubuntu | xenial | * |