---
title: "CVE-2014-0981\n    | Ubuntu"
description: Ubuntu is an open source software operating system that runs from the
  desktop, to the cloud, to all your internet connected things.
url: https://ubuntu.com/security/CVE-2014-0981?format=md
keywords: index, follow
---

# CVE-2014-0981

Publication date 31 March 2014

Last updated 24 July 2024

---

Ubuntu priority

**Medium**

[Why this priority?](https://ubuntu.com/security/cves/about#priority )

Toggle side navigation

## Description

VBox/GuestHost/OpenGL/util/net.c in Oracle VirtualBox before 3.2.22, 4.0.x
before 4.0.24, 4.1.x before 4.1.32, 4.2.x before 4.2.24, and 4.3.x before
4.3.8, when using 3D Acceleration allows local guest OS users to execute
arbitrary code on the Chromium server via crafted Chromium network pointer
in a (1) CR\_MESSAGE\_READBACK or (2) CR\_MESSAGE\_WRITEBACK message to the
VBoxSharedCrOpenGL service, which triggers an arbitrary pointer dereference
and memory corruption. NOTE: this issue was MERGED with CVE-2014-0982
because it is the same type of vulnerability affecting the same set of
versions. All CVE users should reference CVE-2014-0981 instead of
CVE-2014-0982.

## Status

Show unmaintained releases

| Package | Ubuntu Release | Status |
| --- | --- | --- |
| virtualbox | 14.04 LTS trusty | Not in release |
| 13.10 saucy | Fixed 4.2.16-dfsg-3ubuntu0.1 |
| 12.10 quantal | Ignored end of life |
| 12.04 LTS precise | Fixed 4.1.12-dfsg-2ubuntu0.6 |
| 10.04 LTS lucid | Not in release |
| virtualbox-ose | 14.04 LTS trusty | Not in release |
| 13.10 saucy | Not in release |
| 12.10 quantal | Not in release |
| 12.04 LTS precise | Not in release |
| 10.04 LTS lucid | Ignored end of life |

---

* [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)
* [What do statuses mean?](https://ubuntu.com/security/cves/about#statuses)
* [Patch details](https://ubuntu.com/security/CVE-2014-0981?format=md#patch-details)

### Patch details

For informational purposes only. We recommend not to cherry-pick updates. [How can I get the fixes?](https://ubuntu.com/security/cves/about#security)

| Package | Patch details |
| --- | --- |
| virtualbox | * Upstream:   <https://www.virtualbox.org/changeset/50437/vbox> |

## References

* [MITRE](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-0981)
* [NVD](https://nvd.nist.gov/vuln/detail/CVE-2014-0981)
* [Launchpad](https://launchpad.net/bugs/cve/CVE-2014-0981)
* [Debian](https://security-tracker.debian.org/tracker/CVE-2014-0981)

### Other references

* <http://www.coresecurity.com/advisories/oracle-virtualbox-3d-acceleration-multiple-memory-corruption-vulnerabilities>
* <https://www.virtualbox.org/changeset/50437/vbox>
* <http://secunia.com/advisories/57384>
* <http://seclists.org/fulldisclosure/2014/Mar/95>
* <https://www.cve.org/CVERecord?id=CVE-2014-0981>
