LOW · 2.4

CVE-2013-0420

Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The...

Vulnerability Description

Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The previous information was obtained from the January 2013 Oracle CPU. Oracle has not commented on claims from another vendor that this issue is related to an incorrect comparison in the vga_draw_text function in Devices/Graphics/DevVGA.cpp, which can cause VirtualBox to "draw more lines than necessary."

CVSS Score

2.4

LOW

AV:L/AC:H/Au:S/C:N/I:P/A:P
Confidentiality
NONE
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
OpensuseOpensuse12.1
OracleVirtualization4.0
OracleVm Virtualbox4.0

References

FAQ

What is CVE-2013-0420?

CVE-2013-0420 is a vulnerability with a CVSS score of 2.4 (LOW). Unspecified vulnerability in the VirtualBox component in Oracle Virtualization 4.0, 4.1, and 4.2 allows local users to affect integrity and availability via unknown vectors related to Core. NOTE: The...

How severe is CVE-2013-0420?

CVE-2013-0420 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-0420?

Check the references section above for vendor advisories and patch information. Affected products include: Opensuse Opensuse, Oracle Virtualization, Oracle Vm Virtualbox.