Bug 871369 (CVE-2014-0983) - VUL-0: CVE-2014-0983: virtualbox: multiple array index errors
Summary: VUL-0: CVE-2014-0983: virtualbox: multiple array index errors
Status: RESOLVED FIXED
Alias: CVE-2014-0983
Product: SUSE Security Incidents
Classification: Novell Products
Component: Incidents (show other bugs)
Version: unspecified
Hardware: Other openSUSE 13.1
: P3 - Medium : Normal
Target Milestone: ---
Assignee: Michal Seben
QA Contact: Security Team bot
URL: https://smash.suse.de/issue/97484/
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-04-01 11:23 UTC by Alexander Bergmann
Modified: 2015-04-01 13:35 UTC (History)
2 users (show)

See Also:
Found By: Security Response Team
Services Priority:
Business Priority:
Blocker: ---
Marketing QA Status: ---
IT Deployment: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Alexander Bergmann 2014-04-01 11:23:54 UTC
CVE-2014-0983

I'm not sure if openSUSE is affected or not. SLE is not affected. Please check.

Source: US-CERT/NIST

Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle VirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D Acceleration, allow local guest OS users to execute arbitrary code on the Chromium server via certain CR_MESSAGE_OPCODES messages with a crafted index, which are not properly handled by the (1) CR_VERTEXATTRIB4NUBARB_OPCODE to the crServerDispatchVertexAttrib4NubARB function, (2) CR_VERTEXATTRIB1DARB_OPCODE to the crServerDispatchVertexAttrib1dARB function, (3) CR_VERTEXATTRIB1FARB_OPCODE to the crServerDispatchVertexAttrib1fARB function, (4) CR_VERTEXATTRIB1SARB_OPCODE to the crServerDispatchVertexAttrib1sARB function, (5) CR_VERTEXATTRIB2DARB_OPCODE to the crServerDispatchVertexAttrib2dARB function, (6) CR_VERTEXATTRIB2FARB_OPCODE to the crServerDispatchVertexAttrib2fARB function, (7) CR_VERTEXATTRIB2SARB_OPCODE to the crServerDispatchVertexAttrib2sARB function, (8) CR_VERTEXATTRIB3DARB_OPCODE to the crServerDispatchVertexAttrib3dARB function, (9) CR_VERTEXATTRIB3FARB_OPCODE to the crServerDispatchVertexAttrib3fARB function, (10) CR_VERTEXATTRIB3SARB_OPCODE to the crServerDispatchVertexAttrib3sARB function, (11) CR_VERTEXATTRIB4DARB_OPCODE to the crServerDispatchVertexAttrib4dARB function, (12) CR_VERTEXATTRIB4FARB_OPCODE to the crServerDispatchVertexAttrib4fARB function, and (13) CR_VERTEXATTRIB4SARB_OPCODE to the crServerDispatchVertexAttrib4sARB function.

References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2014-0983
http://www.cvedetails.com/cve/CVE-2014-0983/
Comment 1 Swamp Workflow Management 2014-04-01 22:00:35 UTC
bugbot adjusting priority
Comment 2 Johannes Segitz 2015-04-01 13:34:53 UTC
fixed in openSUSEopenSUSE:13.1:Update                     virtualbox  -       7    c83d40f63f91414efb3e8bb01a3cc55d
Comment 3 Johannes Segitz 2015-04-01 13:35:06 UTC
changing state helps ...