[Pkg-virtualbox-devel] Virtualbox 3.2 update due to CVE-2015-3456 (VENOM)

Holger Levsen holger at layer-acht.org
Mon May 18 12:49:18 UTC 2015


Hi,

adding the virtualbox maintainers to cc: :)

On Montag, 18. Mai 2015, Marcin Szewczyk wrote:
> is there going to be a security update to the squeeze-lts Virtualbox?

from IRC:

<h01ger> the debian-security-support package will tell you if a package is 
end-of-life in a distro
<h01ger> virtualbox wasnt part of squeeze
<h01ger> virtualbox is only in squeeze-backports, for that you need to ask the 
maintainer, but backports are generally asked to be security supported
<h01ger> so, yes, virtualbox-ose should be supported
<h01ger> (i have no idea atm if this is practical...)
<h01ger> https://www.virtualbox.org/wiki/Download_Old_Builds_3_2 doesnt have 
an updated for venom yet, but           
https://www.virtualbox.org/wiki/Download_Old_Builds says 3.2 is still 
supported...

Please reply if there are patches "somewhere".


cheers,
	Holger
-------------- next part --------------
A non-text attachment was scrubbed...
Name: signature.asc
Type: application/pgp-signature
Size: 828 bytes
Desc: This is a digitally signed message part.
URL: <http://lists.alioth.debian.org/pipermail/pkg-virtualbox-devel/attachments/20150518/e442a953/attachment.sig>


More information about the Pkg-virtualbox-devel mailing list