Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0,...
Vulnerability Description
Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2013-0420
Credits & Attribution
No credits recorded in the NVD database.
References
- http://lists.opensuse.org/opensuse-updates/2013-02/msg00000.html
- http://www.oracle.com/technetwork/topics/security/cpujan2013-1515902.html
- https://www.virtualbox.org/changeset/44055/vbox
- https://bugzilla.novell.com/show_bug.cgi?id=798776
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A15763
- http://www.mandriva.com/security/advisories?name=MDVSA-2013:150
More from opensuse
View All →Affected Vendor
opensuse
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.