CVE-2014-0981
Summary
| CVE | CVE-2014-0981 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-03-31 14:58:35 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:L/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Oracle | Vm Virtualbox | 4.2.0 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.10 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.12 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.14 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.16 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.18 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.2 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.20 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.4 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.6 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.2.8 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.3.0 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.3.2 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.3.4 | All | All | All |
| Application | Oracle | Vm Virtualbox | 4.3.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Oracle Critical Patch Update - April 2014 | af854a3a-2127-422b-91ae-364da2661108 | www.oracle.com | |
| Full Disclosure: CORE-2014-0002 - Oracle VirtualBox 3D Acceleration Multiple Memory Corruption Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | seclists.org | Exploit |
| Debian -- Security Information -- DSA-2904-1 virtualbox | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Changeset 50437 – Oracle VM VirtualBox | af854a3a-2127-422b-91ae-364da2661108 | www.virtualbox.org | |
| Oracle VirtualBox 3D Acceleration Memory Corruption Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.coresecurity.com | Exploit |
| Security Advisory SA57384 - Oracle VirtualBox 3D Acceleration Multiple Privilege Escalation Vulnerabilities - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| Oracle VirtualBox 3D Acceleration - Multiple Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.exploit-db.com | |
| VirtualBox: Multiple vulnerabilities (GLSA 201612-27) — Gentoo security | af854a3a-2127-422b-91ae-364da2661108 | security.gentoo.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.