NVD Vulnerability Detail
Search Exploit, PoC
CVE-2014-0983
Summary

Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.

Publication Date March 31, 2014, 11:58 p.m.
Registration Date Jan. 26, 2021, 3:05 p.m.
Last Update Nov. 21, 2024, 11:03 a.m.
CVSS2.0 : MEDIUM
Score 6.9
Vector AV:L/AC:M/Au:N/C:C/I:C/A:C
攻撃元区分(AV) ローカル
攻撃条件の複雑さ(AC)
攻撃前の認証要否(Au) 不要
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Get all privileges. いいえ
Get user privileges いいえ
Get other privileges いいえ
User operation required いいえ
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:oracle:vm_virtualbox:4.3.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.14:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.3.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.12:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.3.4:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.18:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.8:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.16:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.3.6:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.20:*:*:*:*:*:*:*
cpe:2.3:a:oracle:vm_virtualbox:4.2.10:*:*:*:*:*:*:*
Related information, measures and tools
Common Vulnerabilities List

JVN Vulnerability Information
Oracle VirtualBox における任意のコードを実行される脆弱性
Title Oracle VirtualBox における任意のコードを実行される脆弱性
Summary

Oracle VirtualBox の VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py によって自動生成されるプログラムには、3D アクセラレーションを使用する場合、配列のインデックスエラーにより、Chromium サーバ上で任意のコードを実行される脆弱性が存在します。

Possible impacts ローカルのゲスト OS ユーザにより、巧妙に細工されたインデックスを持つ特定の CR_MESSAGE_OPCODES メッセージを介して、下記の項目によって適切に処理されないことで、Chromium サーバ上で任意のコードを実行される可能性があります。  (1) crServerDispatchVertexAttrib4NubARB 関数の CR_VERTEXATTRIB4NUBARB_OPCODE (2) crServerDispatchVertexAttrib1dARB 関数の CR_VERTEXATTRIB1DARB_OPCODE (3) crServerDispatchVertexAttrib1fARB 関数の CR_VERTEXATTRIB1FARB_OPCODE (4) crServerDispatchVertexAttrib1sARB 関数の CR_VERTEXATTRIB1SARB_OPCODE (5) crServerDispatchVertexAttrib2dARB 関数の CR_VERTEXATTRIB2DARB_OPCODE (6) crServerDispatchVertexAttrib2fARB 関数の CR_VERTEXATTRIB2FARB_OPCODE (7) crServerDispatchVertexAttrib2sARB 関数の CR_VERTEXATTRIB2SARB_OPCODE (8) crServerDispatchVertexAttrib3dARB 関数の CR_VERTEXATTRIB3DARB_OPCODE (9) crServerDispatchVertexAttrib3fARB 関数の CR_VERTEXATTRIB3FARB_OPCODE (10) crServerDispatchVertexAttrib3sARB 関数の CR_VERTEXATTRIB3SARB_OPCODE (11) crServerDispatchVertexAttrib4dARB 関数の CR_VERTEXATTRIB4DARB_OPCODE (12) crServerDispatchVertexAttrib4fARB 関数の CR_VERTEXATTRIB4FARB_OPCODE (13) crServerDispatchVertexAttrib4sARB 関数の CR_VERTEXATTRIB4SARB_OPCODE
Solution

ベンダより正式な対策が公開されています。ベンダ情報を参照して適切な対策を実施してください。

Publication Date Feb. 13, 2014, midnight
Registration Date April 2, 2014, 10:56 a.m.
Last Update April 2, 2014, 10:56 a.m.
Affected System
オラクル
Oracle VM VirtualBox 4.2.20 までの 4.2.x
Oracle VM VirtualBox 4.3.8 未満の 4.3.x
CVE (情報セキュリティ 共通脆弱性識別子)
CWE (共通脆弱性タイプ一覧)
ベンダー情報
その他
Change Log
No Changed Details Date of change
0 [2014年04月02日]
  掲載
Feb. 17, 2018, 10:37 a.m.