CVE-2014-0981 (CNNVD-201403-590)
中文标题:
Oracle VirtualBox 3D Acceleration 安全漏洞
英文标题:
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x befo...
漏洞描述
中文描述:
Oracle VirtualBox(也称Oracle VM VirtualBox)是美国甲骨文(Oracle)公司的一套跨平台的虚拟化软件。该软件在同一台计算机上支持运行多个操作系统、创建VM群组、共享文件夹等。 Oracle VirtualBox 4.2.x至4.2.20版本和4.3.8之前的4.3.x版本中的VBox/GuestHost/OpenGL/util/net.c文件中的‘crNetRecvReadback’函数存在安全漏洞。当使用3D Acceleration时,本地攻击者可借助CR_MESSAGE_READBACK或CR_MESSAGE_WRITEBACK消息中特制的Chromium Network指针利用该漏洞造成拒绝服务(内存损坏)或在Chromium服务器上执行任意代码。
英文描述:
VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before 4.3.8, when using 3D Acceleration allows local guest OS users to execute arbitrary code on the Chromium server via crafted Chromium network pointer in a (1) CR_MESSAGE_READBACK or (2) CR_MESSAGE_WRITEBACK message to the VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982 because it is the same type of vulnerability affecting the same set of versions. All CVE users should reference CVE-2014-0981 instead of CVE-2014-0982.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| oracle | vm_virtualbox | 4.2.0 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.0:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.2 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.2:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.4 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.4:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.6 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.6:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.8 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.8:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.10 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.10:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.12 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.12:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.14 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.14:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.16 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.16:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.18 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.18:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.20 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.20:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.0 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.0:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.2 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.2:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.4 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.4:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.6 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.6:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
cve.org
cve.org
CVSS评分详情
AV:L/AC:M/Au:N/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2014-0981 |
2025-11-11 15:18:42 | 2025-11-11 07:33:43 |
| NVD | nvd_CVE-2014-0981 |
2025-11-11 14:54:32 | 2025-11-11 07:42:29 |
| CNNVD | cnnvd_CNNVD-201403-590 |
2025-11-11 15:09:26 | 2025-11-11 07:51:19 |
| EXPLOITDB | exploitdb_EDB-32208 |
2025-11-11 15:05:27 | 2025-11-11 08:26:50 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 9 -> 14
- tags_count: 0 -> 6
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201403-590
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 4.4
- cvss_vector: NOT_EXTRACTED -> AV:L/AC:M/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 15
- data_sources: ['cve'] -> ['cve', 'nvd']