Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2014-0981

Опубликовано: 31 мар. 2014
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS2: 4.4

Описание

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.

РелизСтатусПримечание
devel

not-affected

4.3.10-dfsg-1
esm-infra-legacy/trusty

DNE

trusty/esm was DNE [trusty was not-affected [4.3.10-dfsg-1]]
lucid

DNE

precise

released

4.1.12-dfsg-2ubuntu0.6
quantal

ignored

end of life
saucy

released

4.2.16-dfsg-3ubuntu0.1
trusty

not-affected

4.3.10-dfsg-1
trusty/esm

DNE

trusty was not-affected [4.3.10-dfsg-1]
upstream

released

4.3.8

Показывать по

РелизСтатусПримечание
devel

DNE

esm-infra-legacy/trusty

DNE

lucid

ignored

end of life
precise

DNE

quantal

DNE

saucy

DNE

trusty

DNE

trusty/esm

DNE

upstream

not-affected

Показывать по

EPSS

Процентиль: 91%
0.06475
Низкий

4.4 Medium

CVSS2

Связанные уязвимости

nvd
почти 12 лет назад

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.

debian
почти 12 лет назад

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4 ...

github
больше 3 лет назад

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.

EPSS

Процентиль: 91%
0.06475
Низкий

4.4 Medium

CVSS2