CVE-2008-3431
05.08.2008, 19:41
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communication method for IOCTLs and does not properly validate a buffer associated with the Irp object, which allows local users to gain privileges by opening the \\.\VBoxDrv device and calling DeviceIoControl to send a crafted kernel address.Enginsight
Vendor | Product | Version |
---|---|---|
oracle | virtualbox | 𝑥 < 1.6.4 |
𝑥
= Vulnerable software versions

Ubuntu Releases
References