CVE-2014-0982
published 2014-03-31CVE-2014-0982: VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8…
medium4.4CVSS 3.1
AVLACMAuNCPIPAP
EXPLOIT
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
Affected
17 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | virtualbox | < virtualbox 4.3.10-dfsg-1 (sid) | virtualbox 4.3.10-dfsg-1 (sid) |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| oracle | vm_virtualbox | — | — |
| sun | virtualbox | >= 0 < 4.3.10-dfsg-1 | 4.3.10-dfsg-1 |
CVSS provenance
nvd4.4MEDIUMAV:L/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
vendor_debian4.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-0981: virtualbox - VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x befor...
vendor_debian·2014·CVSS 4.4
CVE-2014-0981 [MEDIUM] CVE-2014-0981: virtualbox - VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x befor...
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
Scope: local
sid: resolved (fixed in 4.3.10-dfsg-1)
GHSA
GHSA-jg2m-q6h3-v5jg: VBox/GuestHost/OpenGL/util/net
ghsa_unreviewed·2022-05-14·CVSS 4.4
CVE-2014-0981 [MEDIUM] GHSA-jg2m-q6h3-v5jg: VBox/GuestHost/OpenGL/util/net
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
OSV
CVE-2014-0981: VBox/GuestHost/OpenGL/util/net
osv·2014-03-31·CVSS 4.4
CVE-2014-0981 [MEDIUM] CVE-2014-0981: VBox/GuestHost/OpenGL/util/net
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
No detection rules found.
No writeups or analysis indexed.
http://seclists.org/fulldisclosure/2014/Mar/95http://secunia.com/advisories/57384http://www.coresecurity.com/advisories/oracle-virtualbox-3d-acceleration-multiple-memory-corruption-vulnerabilitieshttp://www.debian.org/security/2014/dsa-2904http://www.exploit-db.com/exploits/32208http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/archive/1/531418/100/0/threadedhttps://security.gentoo.org/glsa/201612-27https://www.virtualbox.org/changeset/50437/vboxhttp://seclists.org/fulldisclosure/2014/Mar/95http://secunia.com/advisories/57384http://www.coresecurity.com/advisories/oracle-virtualbox-3d-acceleration-multiple-memory-corruption-vulnerabilitieshttp://www.debian.org/security/2014/dsa-2904http://www.exploit-db.com/exploits/32208http://www.oracle.com/technetwork/topics/security/cpuapr2014-1972952.htmlhttp://www.securityfocus.com/archive/1/531418/100/0/threadedhttps://security.gentoo.org/glsa/201612-27https://www.virtualbox.org/changeset/50437/vbox
2014-03-31
Published