<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns="http://www.icasi.org/CVRF/schema/cvrf/1.1" xmlns:cvrf="http://www.icasi.org/CVRF/schema/cvrf/1.1">
  <DocumentTitle xml:lang="en">Security update for virtualbox</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2016:2623-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2016-10-25T04:10:15Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2016-10-25T04:10:15Z</InitialReleaseDate>
    <CurrentReleaseDate>2016-10-25T04:10:15Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for virtualbox</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">
This update for virtualbox fixes the following issues:

- Address CVE-2016-5501, CVE-2016-5538, CVE-2016-5605, CVE-2016-5608, CVE-2016-5610, CVE-2016-5611, CVE-2016-5613
  (boo#1005621).
- Reduce memory needs during build.
- Version bump to 5.0.28 (released 2016-10-18 by Oracle)
  This is a maintenance release. The following items were fixed and/or added:
    NAT: Don't exceed the maximum number of &amp;quot;search&amp;quot; suffixes. Patch from bug #15948.
    NAT: fixed parsing of port-forwarding rules with a name which contains a slash (bug #16002)
    NAT Network: when the host has only loopback nameserver that cannot be mapped to the guests
        (e.g. dnsmasq running on 127.0.1.1), make DHCP supply NAT Network DNS proxy as nameserver.
    Bridged Network: prevent flooding syslog with packet allocation error messages (bug #15569)
    USB: fixed a possible crash when detaching a USB device
    Audio: fixes for recording (Mac OS X hosts only)
    Audio: now using Audio Queues on Mac OS X hosts
    OVF: improve importing of VMs created by VirtualBox 5.1
    VHDX: fixed cloning images with VBoxManage cloned (bug #14288)
    Storage: Fixed broken bandwidth limitation when the limit is very low (bug #14982)
    Serial: Fixed high CPU usage with certain USB to serial converters on Linux hosts (bug #7796)
    BIOS: fixed 4bpp scanline calculation (bug #15787)
    VBoxManage: Don't try to set the medium type if there is no change (bug #13850)
    API: fixed initialization of SAS controllers (bug #15972)
    Linux hosts: don't use 32-bit legacy capabilities
    Linux hosts / guests: fix for kernels with CONFIG_CPUMASK_OFFSTACK set (bug #16020)
    Linux Additions: several fixes for X11 guests running non-root X servers
    Linux Additions: fix for Linux 4.7 (bug #15769)
    Linux Additions: fix for the display kmod driver with Linux 4.8 (bugs #15890 and #15896)
    Windows Additions: auto-resizing fixes for Windows 10 guests (bug #15257)
    Windows Additions: fixes for arranging the guest screens in multi-screen scenarios
    Windows Additions / VGA: if the guest's power management turns a virtual screen off, blank the
       corresponding VM window rather than hide the VM window
    Windows Additions: fixed a generic bug which could lead to freezing shared folders (bug #15662) 
- Modify virtualbox-guest-preamble and virtualbox-host-preamble to obsolete old versions of the kernel modules.
  This change should fix the problem in (boo#983629).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      <Description>E-Mail link for openSUSE-SU-2016:2623-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://www.icasi.org/CVRF/schema/prod/1.1">
    <Branch Type="Product Family" Name="openSUSE 13.2">
      <Branch Type="Product Name" Name="openSUSE 13.2">
        <FullProductName ProductID="openSUSE 13.2">openSUSE 13.2</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="python-virtualbox-5.0.28-54.1">
      <FullProductName ProductID="python-virtualbox-5.0.28-54.1">python-virtualbox-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="python-virtualbox-debuginfo-5.0.28-54.1">
      <FullProductName ProductID="python-virtualbox-debuginfo-5.0.28-54.1">python-virtualbox-debuginfo-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-5.0.28-54.1">virtualbox-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-debuginfo-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-debuginfo-5.0.28-54.1">virtualbox-debuginfo-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-debugsource-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-debugsource-5.0.28-54.1">virtualbox-debugsource-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-devel-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-devel-5.0.28-54.1">virtualbox-devel-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-desktop-icons-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-guest-desktop-icons-5.0.28-54.1">virtualbox-guest-desktop-icons-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-tools-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-guest-tools-5.0.28-54.1">virtualbox-guest-tools-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-tools-debuginfo-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-guest-tools-debuginfo-5.0.28-54.1">virtualbox-guest-tools-debuginfo-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-x11-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-guest-x11-5.0.28-54.1">virtualbox-guest-x11-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-guest-x11-debuginfo-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-guest-x11-debuginfo-5.0.28-54.1">virtualbox-guest-x11-debuginfo-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1">
      <FullProductName ProductID="virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-host-source-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-host-source-5.0.28-54.1">virtualbox-host-source-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-qt-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-qt-5.0.28-54.1">virtualbox-qt-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-qt-debuginfo-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-qt-debuginfo-5.0.28-54.1">virtualbox-qt-debuginfo-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-websrv-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-websrv-5.0.28-54.1">virtualbox-websrv-5.0.28-54.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="virtualbox-websrv-debuginfo-5.0.28-54.1">
      <FullProductName ProductID="virtualbox-websrv-debuginfo-5.0.28-54.1">virtualbox-websrv-debuginfo-5.0.28-54.1</FullProductName>
    </Branch>
    <Relationship ProductReference="python-virtualbox-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:python-virtualbox-5.0.28-54.1">python-virtualbox-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="python-virtualbox-debuginfo-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1">python-virtualbox-debuginfo-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-5.0.28-54.1">virtualbox-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-debuginfo-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1">virtualbox-debuginfo-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-debugsource-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1">virtualbox-debugsource-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-devel-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-devel-5.0.28-54.1">virtualbox-devel-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-desktop-icons-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1">virtualbox-guest-desktop-icons-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-tools-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1">virtualbox-guest-tools-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-tools-debuginfo-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1">virtualbox-guest-tools-debuginfo-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-x11-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1">virtualbox-guest-x11-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-guest-x11-debuginfo-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1">virtualbox-guest-x11-debuginfo-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1">virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-host-source-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-host-source-5.0.28-54.1">virtualbox-host-source-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-qt-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-qt-5.0.28-54.1">virtualbox-qt-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-qt-debuginfo-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1">virtualbox-qt-debuginfo-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-websrv-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-websrv-5.0.28-54.1">virtualbox-websrv-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
    <Relationship ProductReference="virtualbox-websrv-debuginfo-5.0.28-54.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE 13.2">
      <FullProductName ProductID="openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1">virtualbox-websrv-debuginfo-5.0.28-54.1 as a component of openSUSE 13.2</FullProductName>
    </Relationship>
  </ProductTree>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5538.</Note>
    </Notes>
    <CVE>CVE-2016-5501</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5501.html</URL>
        <Description>CVE-2016-5501</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core, a different vulnerability than CVE-2016-5501.</Note>
    </Notes>
    <CVE>CVE-2016-5538</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5538.html</URL>
        <Description>CVE-2016-5538</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE.</Note>
    </Notes>
    <CVE>CVE-2016-5605</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5605.html</URL>
        <Description>CVE-2016-5605</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5613.</Note>
    </Notes>
    <CVE>CVE-2016-5608</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5608.html</URL>
        <Description>CVE-2016-5608</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality, integrity, and availability via vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2016-5610</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5610.html</URL>
        <Description>CVE-2016-5610</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect confidentiality via vectors related to Core.</Note>
    </Notes>
    <CVE>CVE-2016-5611</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5611.html</URL>
        <Description>CVE-2016-5611</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
  <Vulnerability xmlns="http://www.icasi.org/CVRF/schema/vuln/1.1" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Unspecified vulnerability in the Oracle VM VirtualBox component before 5.0.28 and 5.1.x before 5.1.8 in Oracle Virtualization allows local users to affect availability via vectors related to Core, a different vulnerability than CVE-2016-5608.</Note>
    </Notes>
    <CVE>CVE-2016-5613</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE 13.2:python-virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:python-virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-debugsource-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-devel-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-desktop-icons-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-tools-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-guest-x11-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-default-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-desktop-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-kmp-pae-debuginfo-5.0.28_k3.16.7_42-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-host-source-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-qt-debuginfo-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-5.0.28-54.1</ProductID>
        <ProductID>openSUSE 13.2:virtualbox-websrv-debuginfo-5.0.28-54.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">Please Install the update.</Description>
        <URL>http://lists.opensuse.org/opensuse-updates/2016-10/msg00090.html</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2016-5613.html</URL>
        <Description>CVE-2016-5613</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1005621</URL>
        <Description>SUSE Bug 1005621</Description>
      </Reference>
    </References>
  </Vulnerability>
</cvrfdoc>
