CVE-2014-0983 (CNNVD-201403-591)
中文标题:
Oracle VirtualBox 数组索引错误漏洞
英文标题:
Multiple array index errors in programs that are automatically generated by VBox/HostServices/Shared...
漏洞描述
中文描述:
Oracle VirtualBox(也称Oracle VM VirtualBox)是美国甲骨文(Oracle)公司的一套跨平台的虚拟化软件。该软件在同一台计算机上支持运行多个操作系统、创建VM群组、共享文件夹等。 Oracle VirtualBox 4.2.x至4.2.20版本和4.3.8之前的4.3.x版本中的文件中的Chromium服务器中存在数组索引错误漏洞,该漏洞源于当处理 CR_VERTEXATTRIB4NUBARB_OPCODE消息时,程序没有正确处理用户提交的输入。本地攻击者可借助特制的消息利用该漏洞造成拒绝服务或执行任意代码。
英文描述:
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| oracle | vm_virtualbox | 4.2.0 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.0:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.2 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.2:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.4 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.4:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.6 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.6:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.8 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.8:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.10 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.10:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.12 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.12:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.14 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.14:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.16 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.16:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.18 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.18:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.2.20 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.2.20:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.0 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.0:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.2 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.2:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.4 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.4:*:*:*:*:*:*:*
|
| oracle | vm_virtualbox | 4.3.6 | - | - |
cpe:2.3:a:oracle:vm_virtualbox:4.3.6:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
参考链接
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
cve.org
cve.org
exploitdb
exploitdb
cve.org
CVSS评分详情
AV:L/AC:M/Au:N/C:C/I:C/A:C
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2014-0983 |
2025-11-11 15:18:42 | 2025-11-11 07:33:43 |
| NVD | nvd_CVE-2014-0983 |
2025-11-11 14:54:32 | 2025-11-11 07:42:29 |
| CNNVD | cnnvd_CNNVD-201403-591 |
2025-11-11 15:09:26 | 2025-11-11 07:51:19 |
| EXPLOITDB | exploitdb_EDB-32208 |
2025-11-11 15:05:27 | 2025-11-11 08:26:50 |
| EXPLOITDB | exploitdb_EDB-34334 |
2025-11-11 15:05:59 | 2025-11-11 08:29:40 |
版本与语言
安全公告
变更历史
查看详细变更
- references_count: 14 -> 17
- tags_count: 6 -> 9
查看详细变更
- references_count: 9 -> 14
- tags_count: 0 -> 6
- data_sources: ['cnnvd', 'cve', 'nvd'] -> ['cnnvd', 'cve', 'exploitdb', 'nvd']
查看详细变更
- vulnerability_type: 未提取 -> 资源管理错误
- cnnvd_id: 未提取 -> CNNVD-201403-591
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- cvss_score: 未提取 -> 6.9
- cvss_vector: NOT_EXTRACTED -> AV:L/AC:M/Au:N/C:C/I:C/A:C
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 15
- data_sources: ['cve'] -> ['cve', 'nvd']