CVE-2014-0983: Medium severity Oracle VM VirtualBox vulnerability
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/serverdispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CRMESSAGEOPCODES messages with a crafted index, which are not properly handled by the (1) CRVERTEXATTRIB4NUBARBOPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CRVERTEXATTRIB1DARBOPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CRVERTEXATTRIB1FARBOPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CRVERTEXATTRIB1SARBOPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CRVERTEXATTRIB2DARBOPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CRVERTEXATTRIB2FARBOPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CRVERTEXATTRIB2SARBOPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CRVERTEXATTRIB3DARBOPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CRVERTEXATTRIB3FARBOPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CRVERTEXATTRIB3SARBOPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CRVERTEXATTRIB4DARBOPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CRVERTEXATTRIB4FARBOPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CRVERTEXATTRIB4SARBOPCODE to the crServerDispatchVertexAttrib4sARB function.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle VirtualBoxto a version that resolves this vulnerability.Fixed in 4.2.20 - Upgrade
Upgrade
Oracle VirtualBoxto a version that resolves this vulnerability.Fixed in 4.3.8
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0983?
CVE-2014-0983 is considered a high severity vulnerability due to the potential for arbitrary code execution.
How do I fix CVE-2014-0983?
To resolve CVE-2014-0983, update Oracle VirtualBox to version 4.3.8 or later.
Who is affected by CVE-2014-0983?
CVE-2014-0983 affects users of Oracle VirtualBox versions 4.2.x through 4.2.20 and 4.3.x before 4.3.8 when using 3D Acceleration.
What kind of attacks can exploit CVE-2014-0983?
CVE-2014-0983 can be exploited by local guest OS users to execute arbitrary code on the host machine.
Is CVE-2014-0983 a remote or local vulnerability?
CVE-2014-0983 is a local vulnerability that requires access to the guest OS environment to be exploited.