{
  "schema_version": "1.7.0",
  "id": "MGASA-2014-0185",
  "published": "2014-04-20T18:54:57Z",
  "modified": "2014-04-20T18:54:50Z",
  "summary": "Updated virtualbox packages fixes security vulnerabilities",
  "details": "VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x\nbefore 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before\n4.3.8, when using 3D Acceleration allows local guest OS users to execute\narbitrary code on the Chromium server via crafted Chromium network pointer\nin a CR_MESSAGE_READBACK or CR_MESSAGE_WRITEBACK message to the\nVBoxSharedCrOpenGL service, which triggers an arbitrary pointer\ndereference and memory corruption (CVE-2014-0981).\n\nMultiple array index errors in programs that are automatically generated\nby VBox/HostServices/SharedOpenGL/crserverlib/server_dispatch.py in Oracle\nVirtualBox 4.2.x through 4.2.20 and 4.3.x before 4.3.8, when using 3D\nAcceleration, allow local guest OS users to execute arbitrary code on the\nChromium server via certain CR_MESSAGE_OPCODES messages with a crafted\nindex, which are not properly handled (CVE-2014-0983).\n\nThe virtualbox packages has been updated to 4.3.10 maintenance release\nthat resolves theese issues and other upstream reported issues (for more\ninfo check the referenced changelog).\n\nThis update also resolves the following:\n- load virtualbox modules on install (mga#8826)\n- missing GUI translations (mga#12578)\n",
  "upstream": [
    "CVE-2014-0981",
    "CVE-2014-0983"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2014-0185.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=13225"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=12578"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=8826"
    },
    {
      "type": "WEB",
      "url": "https://www.debian.org/security/2014/dsa-2904.en.html"
    },
    {
      "type": "WEB",
      "url": "https://www.virtualbox.org/wiki/Changelog"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "kmod-vboxadditions",
        "purl": "pkg:rpm/mageia/kmod-vboxadditions?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.3.10-1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "kmod-virtualbox",
        "purl": "pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.3.10-1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:4",
        "name": "virtualbox",
        "purl": "pkg:rpm/mageia/virtualbox?arch=source&distro=mageia-4"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.3.10-1.1.mga4"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
