CVE-2014-0981: Medium severity Oracle VM VirtualBox vulnerability
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CRMESSAGEREADBACK or (2) CRMESSAGEWRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle VirtualBox VBox/GuestHost/OpenGL/util/net.cto a version that resolves this vulnerability.Fixed in 3.2.22 - Upgrade
Upgrade
Oracle VirtualBox VBox/GuestHost/OpenGL/util/net.cto a version that resolves this vulnerability.Fixed in 4.0.24 - Upgrade
Upgrade
Oracle VirtualBox VBox/GuestHost/OpenGL/util/net.cto a version that resolves this vulnerability.Fixed in 4.1.32 - Upgrade
Upgrade
Oracle VirtualBox VBox/GuestHost/OpenGL/util/net.cto a version that resolves this vulnerability.Fixed in 4.2.24 - Upgrade
Upgrade
Oracle VirtualBox VBox/GuestHost/OpenGL/util/net.cto a version that resolves this vulnerability.Fixed in 4.3.8 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2014-0981 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch CVE-2014-0982
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0981?
CVE-2014-0981 is rated as high severity due to its potential for arbitrary code execution.
How do I fix CVE-2014-0981?
To mitigate CVE-2014-0981, update Oracle VirtualBox to version 4.3.8 or later.
Who is affected by CVE-2014-0981?
CVE-2014-0981 affects users of Oracle VM VirtualBox versions prior to 4.3.8 that utilize 3D acceleration.
What types of attacks are possible with CVE-2014-0981?
CVE-2014-0981 can allow local guest OS users to execute arbitrary code on the host system through crafted Chromium network pointers.
When was CVE-2014-0981 disclosed?
CVE-2014-0981 was disclosed in March 2014.