CVE-2014-0981
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
EPSS 7.03% · 91.6th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:14.04:LTS | virtualbox | 0, 4.2.16-dfsg-3ubuntu1, 4.3.2-dfsg-1ubuntu2 |
Exploit Intelligence
- http://seclists.org/fulldisclosure/2014/Mar/95 (nist-nvd)
- http://www.coresecurity.com/advisories/oracle-virtualbox-3d-acceleration-multiple-memory-corruption-vulnerabilities (nist-nvd)
- 32208 (cve.org)
- Oracle VirtualBox 3D Acceleration Memory Corruption Vulnerability (0day-today)
- Oracle VirtualBox 3D Acceleration Memory Corruption Vulnerability (0day-today)
Timeline
- Mar 11, 2014 PoC Published
- Mar 28, 2014 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 14, 2022 CVE Updated
- Jul 12, 2022 EPSS Score
- Sep 3, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Feb 8, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 2, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2014-0981 third-party-advisory
- http://www.coresecurity.com/advisories/oracle-virtualbox-3d-acceleration-multiple-memory-corruption-vulnerabilities third-party-advisory
- https://www.virtualbox.org/changeset/50437/vbox third-party-advisory
- http://secunia.com/advisories/57384 third-party-advisory
- http://seclists.org/fulldisclosure/2014/Mar/95 third-party-advisory
- https://www.cve.org/CVERecord?id=CVE-2014-0981 third-party-advisory