CVE-2007-1321
published 2007-10-30CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer…
PriorityP425high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.46%
37.3th percentile
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 0.9.0-2 (bookworm) | qemu 0.9.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora_core | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-793p-rv2q-qv42: Integer signedness error in the NE2000 emulator in QEMU 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-1321 [HIGH] GHSA-793p-rv2q-qv42: Integer signedness error in the NE2000 emulator in QEMU 0
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
GHSA
GHSA-w45x-fqpm-jpv8: Heap-based buffer overflow in QEMU 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-5730 [HIGH] CWE-787 GHSA-w45x-fqpm-jpv8: Heap-based buffer overflow in QEMU 0
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
GHSA
GHSA-pqgp-87m3-3238: The NE2000 emulator in QEMU 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-5729 [HIGH] CWE-119 GHSA-pqgp-87m3-3238: The NE2000 emulator in QEMU 0
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
OSV
CVE-2007-5729: The NE2000 emulator in QEMU 0
osv·2007-10-30·CVSS 7.2
CVE-2007-5729 [HIGH] CVE-2007-5729: The NE2000 emulator in QEMU 0
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
OSV
CVE-2007-5730: Heap-based buffer overflow in QEMU 0
osv·2007-10-30·CVSS 7.2
CVE-2007-5730 [HIGH] CVE-2007-5730: Heap-based buffer overflow in QEMU 0
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
OSV
CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0
osv·2007-10-30·CVSS 7.2
CVE-2007-1321 [HIGH] CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Red Hat
QEMU Buffer overflow via crafted "net socket listen" option
vendor_redhat·2007-10-23·CVSS 7.2
CVE-2007-5730 [HIGH] QEMU Buffer overflow via crafted "net socket listen" option
QEMU Buffer overflow via crafted "net socket listen" option
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5729
The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.
Red Hat
xen QEMU NE2000 emulation issues
vendor_redhat·2007-04-20·CVSS 7.2
CVE-2007-1321 [HIGH] xen QEMU NE2000 emulation issues
xen QEMU NE2000 emulation issues
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Debian
CVE-2007-1321: qemu - Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen an...
vendor_debian·2007·CVSS 7.2
CVE-2007-1321 [HIGH] CVE-2007-1321: qemu - Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen an...
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
Debian
CVE-2007-5729: qemu - The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code b...
vendor_debian·2007·CVSS 7.2
CVE-2007-5729 [HIGH] CVE-2007-5729: qemu - The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code b...
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
Debian
CVE-2007-5730: qemu - Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other prod...
vendor_debian·2007·CVSS 7.2
CVE-2007-5730 [HIGH] CVE-2007-5730: qemu - Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other prod...
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
Red Hat
QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
vendor_redhat·CVSS 7.2
CVE-2007-5729 [HIGH] QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
Statement: Not vulnerable. This issue did not affect Xen as shipped with Red Hat Enterprise Linux 5.
Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5729
The Red Hat Product Security has rat
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2007-5729 QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
bugzilla·2007-10-31·CVSS 7.2
CVE-2007-5729 [HIGH] CVE-2007-5729 QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
CVE-2007-5729 QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5729 to the following vulnerability:
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000
"
mtu
"
heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of
"
NE2000 network driver and the socket code,
"
but this is the correct identifier for the mtu overflow vulnerability.
References:
http://taviso.decsystem.org/virtsec.pdf
http://www.debian.org/security/2007/dsa-1284
Discussion:
This issue does not affect Red Hat Enter
Bugzilla
CVE-2007-5730 QEMU Buffer overflow via crafted "net socket listen" option
bugzilla·2007-10-31·CVSS 7.2
CVE-2007-5730 [HIGH] CVE-2007-5730 QEMU Buffer overflow via crafted "net socket listen" option
CVE-2007-5730 QEMU Buffer overflow via crafted "net socket listen" option
Common Vulnerabilities and Exposures assigned an identifier CVE-2007-5730 to the following vulnerability:
Heap-based buffer overflow in QEMU 0.8.2 allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
References:
http://taviso.decsystem.org/virtsec.pdf
http://www.debian.org/security/2007/dsa-1284
Discussion:
See also https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2007-1321 where this
was first discussed before CVE name split
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
bugzilla·2007-09-26·CVSS 7.2
CVE-2007-1366 [HIGH] CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
+++ This bug was initially created as a clone of Bug #238723 +++
Not sure if these affect any qemu versions in Fedora, but here goes:
http://www.vuxml.org/freebsd/0ac89b39-f829-11db-b55c-000e0c6d38a9.html
"Several vulnerabilities have been discovered in the QEMU processor emulator,
which may lead to the execution of arbitrary code or denial of service. The
Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video
driver performs insufficient bounds checking, which might allow the execution of
arbitrary code through a heap overflow.
CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
bugzilla·2007-05-02·CVSS 7.2
CVE-2007-1366 [HIGH] CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
Not sure if these affect any qemu versions in Fedora, but here goes:
http://www.vuxml.org/freebsd/0ac89b39-f829-11db-b55c-000e0c6d38a9.html
"Several vulnerabilities have been discovered in the QEMU processor emulator,
which may lead to the execution of arbitrary code or denial of service. The
Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video
driver performs insufficient bounds checking, which might allow the execution of
arbitrary code through a heap overflow.
CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the socket code
perform insufficient input validation, which might al
Bugzilla
CVE-2007-1321 xen QEMU NE2000 emulation issues
bugzilla·2007-04-20·CVSS 7.2
CVE-2007-1321 [HIGH] CVE-2007-1321 xen QEMU NE2000 emulation issues
CVE-2007-1321 xen QEMU NE2000 emulation issues
* NE2000 "mtu" heap overflow
Ethernet frames written into the ne2000 device registers do not have
their packet size checked against the mtu before being transfered,
resulting in large values in the TCNT register overwriting a heap
buffer with arbitrary attacker controller data from the devices memory
banks. The pcnet32 card may also be affected (the attached patch would
solve it if so).
* QEMU "net socket" heap overflow.
QEMU does not perform adequate sanity checking on data received via
the "net socket listen" option, resulting in an exploitable heap
overflow. This could be reached by attackers on the host, or other
guests.
* QEMU NE2000 "receive" integer signedness error
Nonsensical values in specific device registers can result in sanity
http://osvdb.org/35495http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/27047http://secunia.com/advisories/27072http://secunia.com/advisories/27103http://secunia.com/advisories/27486http://secunia.com/advisories/29129http://securitytracker.com/id?1018761http://taviso.decsystem.org/virtsec.pdfhttp://www.attrition.org/pipermail/vim/2007-October/001842.htmlhttp://www.debian.org/security/2007/dsa-1284http://www.mandriva.com/security/advisories?name=MDKSA-2007:203http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.redhat.com/support/errata/RHSA-2007-0323.htmlhttp://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9302https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.htmlhttp://osvdb.org/35495http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/27047http://secunia.com/advisories/27072http://secunia.com/advisories/27103http://secunia.com/advisories/27486http://secunia.com/advisories/29129http://securitytracker.com/id?1018761http://taviso.decsystem.org/virtsec.pdfhttp://www.attrition.org/pipermail/vim/2007-October/001842.htmlhttp://www.debian.org/security/2007/dsa-1284http://www.mandriva.com/security/advisories?name=MDKSA-2007:203http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.redhat.com/support/errata/RHSA-2007-0323.htmlhttp://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9302https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.htmlhttps://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html
2007-10-30
Published