CVE-2013-0420

Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core.  NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."
Severity
UNKNOWN
AV:L/AC:H/Au:S/C:N/I:P/A:P
Atk. Vector
LOCAL
Atk. Complexity
HIGH
Base Score
CVSS 3.x
EPSS Score
Percentile: 80%
VendorProductVersion
opensuseopensuse
12.1
opensuseopensuse
12.2
oraclevirtualization
4.0
oraclevirtualization
4.1
oraclevirtualization
4.2
oraclevm_virtualbox
4.0
oraclevm_virtualbox
4.1.0
oraclevm_virtualbox
4.2.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
virtualbox
sid/contrib
7.0.20-dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
virtualbox
trusty
dne
saucy
not-affected
raring
ignored
quantal
ignored
precise
Fixed 4.1.12-dfsg-2ubuntu0.6
released
oneiric
ignored
lucid
dne
hardy
dne
virtualbox-ose
trusty
dne
saucy
dne
raring
dne
quantal
dne
precise
dne
oneiric
dne
lucid
ignored
hardy
ignored