Showing posts with label Venom. Show all posts
Showing posts with label Venom. Show all posts

Sunday, 17 May 2015

Oracle Closed Venom Vulnerability In Virtual Box And Linux



This week it was announced that a serious vulnerability is present in various virtualization solutions allow an attacker from a virtual machine can "escape" to then fully take over the guest OS. Many companies would thereby risk.

The vulnerability, which is named " Venom got ", is present in the floppy disk controller (FDC) of QEMU (Quick Emulator). An attacker must therefore have access to the FDC in order to carry out his malicious code within the virtual machine. The vulnerable code is used by various virtualization platforms and appliances, including those from Oracle.

It comes to know different products, as the software giant late. For Oracle Linux, Oracle VirtualBox, Oracle VM and Oracle Virtual Compute Appliance have been updates released to stop the leak. In the case of Oracle Database Appliance, Exadata Database Machine, Exalogic Elastic Cloud and Exalytics In-Memory Machine, which is also likely to be vulnerable, no updates are available yet. The list of patched products in the advisory However, Oracle is continuously updated.

Wednesday, 13 May 2015

Virtual Floppy Drive Creates Serious Leak In Virtual Machines


Researchers have discovered an eleven year old and serious vulnerability in various virtualization platforms, allowing an attacker to escape from virtual machines. The vulnerability has security Crowd Strike called " Venom got "and is located in the virtual floppy disk controller (FDC) of QEMU. QEMU, which stands for Quick Emulator, is free and open source virtualization software.

The vulnerable code is used by various appliances and virtualization platforms including Xen, KVM and QEMU client. Popular virtualization software such as VMware, Microsoft Hyper-V hypervisor and Bochs is not vulnerable. By using the vulnerability that may escape an attacker out of the virtual machine and then, whether or not to get over the other virtual machines, access to the network. While floppy disks no longer be used, would provide many standard virtualization solutions from a virtual floppy drive.

By attacking the Venom leak can get assailants as Crowd Strike access to intellectual property of companies, as well as sensitive and personally identifiable information. Possibly would be thousands of organizations and millions of users of sensitive virtual machines use risk. The leak would be present in the code since 2004. Yet there are no attacks observed in the wild. To carry out the attack must have an attacker or malware on root or administrator privileges on the host system.

For QEMU Project, Xen Project and Red Hat have now been released security updates. Another solution is to configure the virtual machine hypervisor in a certain way, the impact of the vulnerability can reduce or even prevent altogether. Something Crowd Strike in the advisory explains.