CVE-2014-0406: Low severity Oracle VM VirtualBox vulnerability
Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4 allows local users to affect integrity and availability via unknown vectors related to Core, a different vulnerability than CVE-2014-0404.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0406?
CVE-2014-0406 is classified as a local vulnerability that may affect the integrity and availability of systems running affected versions of Oracle VM VirtualBox.
How do I fix CVE-2014-0406?
To mitigate CVE-2014-0406, upgrade Oracle VM VirtualBox to a version that is 3.2.20 or higher, or 4.0.22 or higher.
Which versions of Oracle VM VirtualBox are affected by CVE-2014-0406?
CVE-2014-0406 affects multiple versions of Oracle VM VirtualBox prior to 3.2.20, 4.0.22, 4.1.30, 4.2.20, and 4.3.4.
What types of security issues does CVE-2014-0406 cause?
CVE-2014-0406 allows local users to affect system integrity and availability through unspecified vectors.
Is there a workaround for CVE-2014-0406?
No official workaround is provided for CVE-2014-0406; the best remediation is to update to the patched versions of Oracle VM VirtualBox.