---
title: "CVE-2016-0602\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2016-0602?format=md
keywords: index, follow
---

# CVE-2016-0602

Publication date 21 January 2016

Last updated 24 July 2024

---

Ubuntu priority

**Negligible**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle
Virtualization VirtualBox before 5.0.14 allows local users to affect
confidentiality, integrity, and availability via unknown vectors related to
Windows Installer. NOTE: the previous information is from the January 2016
CPU. Oracle has not commented on third-party claims that this is an
untrusted search path issue that allows local users to gain privileges via
a Trojan horse dll in the "application directory."

[Read the notes from the security team](https://ubuntu.com/security/CVE-2016-0602?format=md#notes)

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| virtualbox | 15.10 wily | Fixed 5.0.14-dfsg-0ubuntu1.15.10.1 |
| 15.04 vivid | Not affected |
| 14.04 LTS trusty | Not in release |
| 12.04 LTS precise | Not affected |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)

## Notes

---

### [sbeattie](https://launchpad.net/~sbeattie)

windows installer, 5.0.x only

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0602)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2016-0602)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2016-0602)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2016-0602)

### Other references

* <http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html#AppendixOVIR>
* <http://www.oracle.com/technetwork/topics/security/cpujan2016-2367955.html>
* <https://www.cve.org/CVERecord?id=CVE-2016-0602>
