Vulnerabilities > CVE-2014-0981 - Resource Management Errors vulnerability in Oracle VM Virtualbox

047910
CVSS 4.4 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
oracle
CWE-399
nessus
exploit available

Summary

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionOracle VirtualBox 3D Acceleration - Multiple Vulnerabilities. CVE-2014-0981,CVE-2014-0982,CVE-2014-0983. Dos exploits for multiple platform
fileexploits/multiple/dos/32208.txt
idEDB-ID:32208
last seen2016-02-03
modified2014-03-12
platformmultiple
port
published2014-03-12
reporterCore Security
sourcehttps://www.exploit-db.com/download/32208/
titleOracle VirtualBox 3D Acceleration - Multiple Vulnerabilities
typedos

Nessus

  • NASL familyWindows
    NASL idVIRTUALBOX_4_3_8.NASL
    descriptionThe remote host contains a version of Oracle VM VirtualBox that is 3.2.x prior to 3.2.22, 4.0.24, 4.1.32, 4.2.24 or 4.3.8. It is, therefore, potentially affected by the following vulnerabilities : - An input validation error exists in the function
    last seen2020-06-01
    modified2020-06-02
    plugin id72985
    published2014-04-16
    reporterThis script is Copyright (C) 2014-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/72985
    titleOracle VM VirtualBox < 3.2.22 / 4.0.24 / 4.1.32 / 4.2.24 / 4.3.8 Multiple Memory Corruption
  • NASL familyDebian Local Security Checks
    NASL idDEBIAN_DSA-2904.NASL
    descriptionFrancisco Falcon discovered that missing input sanitizing in the 3D acceleration code in VirtualBox could lead to the execution of arbitrary code on the host system.
    last seen2020-03-17
    modified2014-04-16
    plugin id73534
    published2014-04-16
    reporterThis script is Copyright (C) 2014-2020 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/73534
    titleDebian DSA-2904-1 : virtualbox - security update
  • NASL familyGentoo Local Security Checks
    NASL idGENTOO_GLSA-201612-27.NASL
    descriptionThe remote host is affected by the vulnerability described in GLSA-201612-27 (VirtualBox: Multiple vulnerabilities) Multiple vulnerabilities have been discovered in VirtualBox. Please review the CVE identifiers referenced below for details. Impact : Local attackers could cause a Denial of Service condition, execute arbitrary code, or escalate their privileges. Workaround : There is no known workaround at this time.
    last seen2020-06-01
    modified2020-06-02
    plugin id95695
    published2016-12-12
    reporterThis script is Copyright (C) 2016-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/95695
    titleGLSA-201612-27 : VirtualBox: Multiple vulnerabilities (Venom)

Packetstorm

data sourcehttps://packetstormsecurity.com/files/download/125660/CORE-2014-0002.txt
idPACKETSTORM:125660
last seen2016-12-05
published2014-03-11
reporterCore Security Technologies
sourcehttps://packetstormsecurity.com/files/125660/Oracle-VirtualBox-3D-Acceleration-Memory-Corruption.html
titleOracle VirtualBox 3D Acceleration Memory Corruption

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:85507
last seen2017-11-19
modified2014-07-01
published2014-07-01
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-85507
titleOracle VirtualBox 3D Acceleration - Multiple Vulnerabilities