CVE-2007-1320
published 2007-05-02CVE-2007-1320: Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.49%
39.1th percentile
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
Affected
31 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 0.9.1+svn20081101-1 (bookworm) | qemu 0.9.1+svn20081101-1 (bookworm) |
| debian | qemu | < qemu 0.9.0-2 (bookworm) | qemu 0.9.0-2 (bookworm) |
| debian | qemu | < qemu 2.1+dfsg-9 (bookworm) | qemu 2.1+dfsg-9 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora_core | — | — |
| kvm_qumranet | kvm | <= 81 | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qemu | qemu | < 0.10.0 | 0.10.0 |
| qemu | qemu | <= 2.1.2 | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 0.9.1+svn20081101-1 | 0.9.1+svn20081101-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-9 | 2.1+dfsg-9 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.1+svn20081101-1 | 0.9.1+svn20081101-1 |
| qemu | qemu | >= 0 < 2.1+dfsg-9 | 2.1+dfsg-9 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g3gg-2j77-h4r4: Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga
ghsa_unreviewed·2022-05-17·CVSS 7.2
CVE-2014-8106 [HIGH] CWE-119 GHSA-g3gg-2j77-h4r4: Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
GHSA
GHSA-gq7c-3rjh-ggvh: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
ghsa_unreviewed·2022-05-02·CVSS 7.2
CVE-2008-4539 [HIGH] CWE-119 GHSA-gq7c-3rjh-ggvh: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
GHSA
GHSA-g9wg-j7vq-xx6p: Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0
ghsa_unreviewed·2022-05-01
CVE-2007-1320 [HIGH] CWE-787 GHSA-g9wg-j7vq-xx6p: Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
OSV
CVE-2014-8106: Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga
osv·2014-12-08·CVSS 7.2
CVE-2014-8106 [HIGH] CVE-2014-8106: Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
OSV
CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
osv·2008-12-29·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539: Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local use
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
OSV
CVE-2007-1320: Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0
osv·2007-05-02·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320: Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
Red Hat
qemu: cirrus: insufficient blit region checks
vendor_redhat·2014-12-04·CVSS 7.2
CVE-2014-8106 [HIGH] CWE-20 qemu: cirrus: insufficient blit region checks
qemu: cirrus: insufficient blit region checks
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
It was found that the Cirrus blit region checks were insufficient. A privileged guest user could use this flaw to write outside of VRAM-allocated buffer boundaries in the host's QEMU process address space with attacker-provided data.
Statement: This issue affects the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6, a future update may address this flaw.
This issue affects the kvm packages as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in
Debian
CVE-2014-8106: qemu - Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) ...
vendor_debian·2014·CVSS 7.2
CVE-2014-8106 [HIGH] CVE-2014-8106: qemu - Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) ...
Heap-based buffer overflow in the Cirrus VGA emulator (hw/display/cirrus_vga.c) in QEMU before 2.2.0 allows local guest users to execute arbitrary code via vectors related to blit regions. NOTE: this vulnerability exists because an incomplete fix for CVE-2007-1320.
Scope: local
bookworm: resolved (fixed in 2.1+dfsg-9)
bullseye: resolved (fixed in 2.1+dfsg-9)
forky: resolved (fixed in 2.1+dfsg-9)
sid: resolved (fixed in 2.1+dfsg-9)
trixie: resolved (fixed in 2.1+dfsg-9)
Red Hat
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
vendor_redhat·2008-10-29·CVSS 7.2
CVE-2008-4539 [HIGH] kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Debian
CVE-2008-4539: qemu - Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kv...
vendor_debian·2008·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539: qemu - Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kv...
Heap-based buffer overflow in the Cirrus VGA implementation in (1) KVM before kvm-82 and (2) QEMU on Debian GNU/Linux and Ubuntu might allow local users to gain privileges by using the VNC console for a connection, aka the LGD-54XX "bitblt" heap overflow. NOTE: this issue exists because of an incorrect fix for CVE-2007-1320.
Scope: local
bookworm: resolved (fixed in 0.9.1+svn20081101-1)
bullseye: resolved (fixed in 0.9.1+svn20081101-1)
forky: resolved (fixed in 0.9.1+svn20081101-1)
sid: resolved (fixed in 0.9.1+svn20081101-1)
trixie: resolved (fixed in 0.9.1+svn20081101-1)
Red Hat
xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
vendor_redhat·2007-04-20·CVSS 7.2
CVE-2007-1320 [HIGH] xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
Debian
CVE-2007-1320: qemu - Multiple heap-based buffer overflows in the cirrus_invalidate_region function in...
vendor_debian·2007·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320: qemu - Multiple heap-based buffer overflows in the cirrus_invalidate_region function in...
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8106 qemu: cirrus: insufficient blit region checks
bugzilla·2014-12-01·CVSS 7.2
CVE-2014-8106 [HIGH] CVE-2014-8106 qemu: cirrus: insufficient blit region checks
CVE-2014-8106 qemu: cirrus: insufficient blit region checks
It was found that the Cirrus blit region checks were insufficient.
A privileged guest user could use this flaw to to write outside of vram
allocated buffer boundaries in the host's qemu process address space with
attacker provided data.
Acknowledgements:
This issue was discovered by Paolo Bonzini of Red Hat.
Discussion:
Upstream patch submission:
http://lists.gnu.org/archive/html/qemu-devel/2014-12/msg00508.html
---
Created qemu tracking bugs for this issue:
Affects: fedora-all [bug 1170612]
---
Note that this really is an incorrect / incomplete CVE-2007-1320 (bug 237342) fix issue.
---
Statement:
This issue affects the qemu-kvm packages as shipped with Red Hat Enterprise Linux 6, a future update may address this fl
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
bugzilla·2008-11-11·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
kvm-74-6.fc10 has been submitted as an update for Fedora 10.
http://admin.fedoraproject.org/updates/kvm-74-6.fc10
Discussion:
kvm-74-6.fc10 has been pushed to the Fedora 10 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
bugzilla·2008-10-14·CVSS 7.2
CVE-2008-4539 [HIGH] CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
CVE-2008-4539 kvm/qemu/xen: Incomplete upstream fix for CVE-2007-1320
Created attachment 320281
Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (CVE-2007-1320)
Jan Niehusmann discovered that the upstream fix for the CVE-2007-1320 is
incomplete and still allows local users to cause a heap-based buffer overlow,
when connecting via the VNC console.
Steps to reproduce:
No reproducer.
Upstream qemu patch for the initial CVE-2007-1320 issue:
https://svn.pardus.org.tr/pardus/2007/applications/emulators/qemu/files/CVE-2007-1320.patch
Proposed upstream correction of this patch - see attachment.
Discussion:
QEMU upstream commit:
http://git.kernel.dk/?p=qemu.git;a=commitdiff;h=65d35a09979e63541afc5bfc595b9f1b1b4ae069
More on current status of thi
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
bugzilla·2008-05-27·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 8]
kvm-60-6.fc8 has been submitted as an update for Fedora 8
Discussion:
*** This bug has been marked as a duplicate of 237342 ***
---
kvm-60-6.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
---
It appears this beast is still alive.
CVE-2008-4539 is its new name.
---
kvm-60-7.fc8 has been submitted as an update for Fedora 8.
http://admin.fedoraproject.org/updates/kvm-60-7.fc8
---
kvm-60-7.fc8 has been pushed to the Fedora 8 stable repository. If problems still persist, please make note of it in this bug report.
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
bugzilla·2008-05-27·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow [Fedora 9]
kvm-65-7.fc9 has been pushed to the Fedora 9 stable repository. If problems still persist, please make note of it in this bug report.
Discussion:
It appears this beast is still alive.
CVE-2008-4539 is its new name.
---
kvm-65-11.fc9 has been submitted as an update for Fedora 9.
http://admin.fedoraproject.org/updates/kvm-65-11.fc9
---
kvm-65-11.fc9 has been pushed to the Fedora 9 testing repository. If problems still persist, please make note of it in this bug report.
If you want to test the update, you can install it with
su -c 'yum --enablerepo=updates-testing update kvm'. You can provide feedback for this update here: http://admin.fedoraproject.org/updates/F9/FEDORA-2008-9571
---
kvm-65-13.fc9 has been subm
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
bugzilla·2007-09-26·CVSS 7.2
CVE-2007-1366 [HIGH] CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
+++ This bug was initially created as a clone of Bug #238723 +++
Not sure if these affect any qemu versions in Fedora, but here goes:
http://www.vuxml.org/freebsd/0ac89b39-f829-11db-b55c-000e0c6d38a9.html
"Several vulnerabilities have been discovered in the QEMU processor emulator,
which may lead to the execution of arbitrary code or denial of service. The
Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video
driver performs insufficient bounds checking, which might allow the execution of
arbitrary code through a heap overflow.
CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
bugzilla·2007-05-02·CVSS 7.2
CVE-2007-1366 [HIGH] CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
Not sure if these affect any qemu versions in Fedora, but here goes:
http://www.vuxml.org/freebsd/0ac89b39-f829-11db-b55c-000e0c6d38a9.html
"Several vulnerabilities have been discovered in the QEMU processor emulator,
which may lead to the execution of arbitrary code or denial of service. The
Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video
driver performs insufficient bounds checking, which might allow the execution of
arbitrary code through a heap overflow.
CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the socket code
perform insufficient input validation, which might al
Bugzilla
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
bugzilla·2007-04-20·CVSS 7.2
CVE-2007-1320 [HIGH] CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
CVE-2007-1320 xen/qemu Cirrus LGD-54XX "bitblt" Heap Overflow
The cirrus_invalidate_region() routine used during video-to-video copy
operations in the cirrus vga extension code omits bounds checking in
multiple locations, allowing you to overwrite adjacent buffers by
attempting to mark non-existent regions as dirty. Successful
exploitation would result in a complete compromise of the qemu
process. Additionally multiple bitblt operations omit bounds checking,
where the srcpitch or dstpitch coefficients cause the operation to
exceed the bounds of the vram buffer.
Discussion:
Upstream applied this fix:
http://xenbits.xensource.com/xen-unstable.hg?rev/9e86260b95a4
---
This request was evaluated by Red Hat Product Management for inclusion in a Red
Hat Enterprise Linux maintenance release.
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://osvdb.org/35494http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/27047http://secunia.com/advisories/27085http://secunia.com/advisories/27103http://secunia.com/advisories/27486http://secunia.com/advisories/29129http://secunia.com/advisories/30413http://secunia.com/advisories/33568http://taviso.decsystem.org/virtsec.pdfhttp://www.debian.org/security/2007/dsa-1284http://www.debian.org/security/2007/dsa-1384http://www.mandriva.com/security/advisories?name=MDKSA-2007:203http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.redhat.com/support/errata/RHSA-2007-0323.htmlhttp://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10315https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00706.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00935.htmlhttp://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://osvdb.org/35494http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/27047http://secunia.com/advisories/27085http://secunia.com/advisories/27103http://secunia.com/advisories/27486http://secunia.com/advisories/29129http://secunia.com/advisories/30413http://secunia.com/advisories/33568http://taviso.decsystem.org/virtsec.pdfhttp://www.debian.org/security/2007/dsa-1284http://www.debian.org/security/2007/dsa-1384http://www.mandriva.com/security/advisories?name=MDKSA-2007:203http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.redhat.com/support/errata/RHSA-2007-0323.htmlhttp://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10315https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00706.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-May/msg00935.html
2007-05-02
Published