<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet type="text/xsl" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1687073.xsl"?>
<?xml-stylesheet type="text/css" href="http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/1686935.css"?>
<cvrf:cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
   <DocumentTitle xml:lang="en">Oracle Security Alert for CVE-2015-3456 - Beta Oracle CVRF</DocumentTitle>
   <DocumentType xml:lang="en">Oracle Security Alert</DocumentType>
   <DocumentPublisher Type="Vendor"/>
   <DocumentTracking>
      <Identification>
         <ID>CVE-2015-3456</ID>
      </Identification>
      <Status>Final</Status>
      <Version>1.0</Version>
      <RevisionHistory>
         <Revision>
            <Number>1.0</Number>
            <Date>2015-05-14T13:00:00-07:00</Date>
            <Description>Initial Distribution</Description>
         </Revision>
      </RevisionHistory>
      <InitialReleaseDate>2015-05-14T13:00:00-07:00</InitialReleaseDate>
      <CurrentReleaseDate>2015-05-14T13:00:00-07:00</CurrentReleaseDate>
   </DocumentTracking>
   <DocumentNotes>
      <Note Audience="All" Ordinal="1" Title="Summary" Type="Summary" xml:lang="en">This document contains descriptions of Oracle product security vulnerabilities which have had fixes released for all supported versions and platforms for the associated product.  Additional information regarding these vulnerabilities including fix distribution information can be found at the Oracle sites referenced in this document.</Note>
   </DocumentNotes>
   <DocumentDistribution>This document is published at: http://www.oracle.com/ocom/groups/public/@otn/documents/webcontent/2543038.xml</DocumentDistribution>
   <DocumentReferences>
      <Reference Type="External">
         <URL>http://www.oracle.com/technetwork/topics/security/alert-cve-2015-3456-2542656.html</URL>
         <Description>URL to html version of Advisory</Description>
      </Reference>
   </DocumentReferences>
   <Acknowledgments/>
   <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
      <Branch Name="Oracle" Type="Vendor">
         <Branch Name="Oracle Linux" Type="Product Family">
            <Branch Name="Linux OS" Type="Product Name">
               <Branch Name="5" Type="Product Version">
                  <FullProductName ProductID="P-1309V-5">Linux OS Version 5</FullProductName>
               </Branch>
               <Branch Name="6" Type="Product Version">
                  <FullProductName ProductID="P-1309V-6">Linux OS Version 6</FullProductName>
               </Branch>
               <Branch Name="7" Type="Product Version">
                  <FullProductName ProductID="P-1309V-7">Linux OS Version 7</FullProductName>
               </Branch>
            </Branch>
         </Branch>
         <Branch Name="Oracle Virtualization" Type="Product Family">
            <Branch Name="Oracle VM" Type="Product Name">
               <Branch Name="2.2" Type="Product Version">
                  <FullProductName ProductID="P-4455V-2.2">Oracle VM Version 2.2</FullProductName>
               </Branch>
               <Branch Name="3.2" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.2">Oracle VM Version 3.2</FullProductName>
               </Branch>
               <Branch Name="3.3" Type="Product Version">
                  <FullProductName ProductID="P-4455V-3.3">Oracle VM Version 3.3</FullProductName>
               </Branch>
            </Branch>
            <Branch Name="Oracle VM VirtualBox" Type="Product Name">
               <Branch Name="3.2" Type="Product Version">
                  <FullProductName ProductID="P-8370V-3.2">Oracle VM VirtualBox Version 3.2</FullProductName>
               </Branch>
               <Branch Name="4.0" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.0">Oracle VM VirtualBox Version 4.0</FullProductName>
               </Branch>
               <Branch Name="4.1" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.1">Oracle VM VirtualBox Version 4.1</FullProductName>
               </Branch>
               <Branch Name="4.2" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.2">Oracle VM VirtualBox Version 4.2</FullProductName>
               </Branch>
               <Branch Name="4.3 prior to 4.3.28" Type="Product Version">
                  <FullProductName ProductID="P-8370V-4.3 prior to 4.3.28">Oracle VM VirtualBox Version 4.3 prior to 4.3.28</FullProductName>
               </Branch>
            </Branch>
         </Branch>
      </Branch>
   </ProductTree>
   <Vulnerability Ordinal="1" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3456</Title>
      <Notes>
         <Note Audience="All" Ordinal="1" Title="Details" Type="Details">Vulnerability in the Oracle Linux component of Oracle Linux (subcomponent: Xen, Qemu-KVM).  Supported versions that are affected are 5, 6 and  7. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-1309V-5</ProductID>
            <ProductID>P-1309V-6</ProductID>
            <ProductID>P-1309V-7</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2015-3456</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/alert-cve-2015-3456-2542656.html</URL>
            <ProductID>P-1309V-5</ProductID>
            <ProductID>P-1309V-6</ProductID>
            <ProductID>P-1309V-7</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="2" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3456</Title>
      <Notes>
         <Note Audience="All" Ordinal="2" Title="Details" Type="Details">Vulnerability in the Oracle VM component of Oracle Virtualization (subcomponent: Xen Hypervisor).  Supported versions that are affected are 2.2, 3.2 and  3.3. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.  CVSS Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-4455V-2.2</ProductID>
            <ProductID>P-4455V-3.2</ProductID>
            <ProductID>P-4455V-3.3</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2015-3456</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/alert-cve-2015-3456-2542656.html</URL>
            <ProductID>P-4455V-2.2</ProductID>
            <ProductID>P-4455V-3.2</ProductID>
            <ProductID>P-4455V-3.3</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
   <Vulnerability Ordinal="3" xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1">
      <Title>CVE-2015-3456</Title>
      <Notes>
         <Note Audience="All" Ordinal="3" Title="Details" Type="Details">Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core).  Supported versions that are affected are 3.2, 4.0, 4.1, 4.2 and  4.3 prior to 4.3.28. Very difficult to exploit vulnerability requiring logon to Operating System.  Successful attack of this vulnerability can result in unauthorized Operating System takeover including arbitrary code execution.   Note: The CVSS score assumes that the virtualization software is running on the
host operating system as a privileged user. When this is not the case, the
corresponding CVSS impact scores for Confidentiality, Integrity, and
Availability are "Partial+" instead of "Complete", lowering the CVSS Base
Score. For example, a Base Score of 6.2 becomes 3.7. CVSS Base Score 6.2 (Confidentiality, Integrity and Availability impacts).  CVSS V2 Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).  Oracle Vector: (AV:L/AC:H/Au:N/C:C/I:C/A:C).</Note>
      </Notes>
      <Involvements>
         <Involvement Party="Vendor" Status="Completed">
            <Description>Fix has been released</Description>
         </Involvement>
      </Involvements>
      <CVE>CVE-2015-3456</CVE>
      <ProductStatuses>
         <Status Type="Known Affected">
            <ProductID>P-8370V-3.2</ProductID>
            <ProductID>P-8370V-4.0</ProductID>
            <ProductID>P-8370V-4.1</ProductID>
            <ProductID>P-8370V-4.2</ProductID>
            <ProductID>P-8370V-4.3 prior to 4.3.28</ProductID>
         </Status>
      </ProductStatuses>
      <CVSSScoreSets>
         <ScoreSet>
            <BaseScore>6.2</BaseScore>
            <Vector>AV:L/AC:H/Au:N/C:C/I:C/A:C</Vector>
         </ScoreSet>
      </CVSSScoreSets>
      <Remediations>
         <Remediation Type="Vendor Fix">
            <Description>CVE-2015-3456</Description>
            <Entitlement xml:lang="en">Oracle customers with valid support contracts</Entitlement>
            <URL>http://www.oracle.com/technetwork/topics/security/alert-cve-2015-3456-2542656.html</URL>
            <ProductID>P-8370V-3.2</ProductID>
            <ProductID>P-8370V-4.0</ProductID>
            <ProductID>P-8370V-4.1</ProductID>
            <ProductID>P-8370V-4.2</ProductID>
            <ProductID>P-8370V-4.3 prior to 4.3.28</ProductID>
         </Remediation>
      </Remediations>
   </Vulnerability>
</cvrf:cvrfdoc>
