CVE-2007-1321

13 documents7 sources
Severity
7.2HIGH
EPSS
0.0%
top 87.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30
Latest updateMay 1

Description

Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages3 packages

Debianqemu< 0.9.0-2+3
NVDqemu/qemu0.8.2

Also affects: Debian Linux 3.1, 4.0, Fedora 7

🔴Vulnerability Details

3
GHSA
GHSA-793p-rv2q-qv42: Integer signedness error in the NE2000 emulator in QEMU 02022-05-01
CVEList
CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 02007-10-30
OSV
CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 02007-10-30

📋Vendor Advisories

4
Red Hat
QEMU Buffer overflow via crafted "net socket listen" option2007-10-23
Red Hat
xen QEMU NE2000 emulation issues2007-04-20
Debian
CVE-2007-1321: qemu - Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen an...2007
Red Hat
QEMU NE2000 Buffer overflow triggerable by frames larger than MTU

💬Community

5
Bugzilla
CVE-2007-5729 QEMU NE2000 Buffer overflow triggerable by frames larger than MTU2007-10-31
Bugzilla
CVE-2007-5730 QEMU Buffer overflow via crafted "net socket listen" option2007-10-31
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities2007-09-26
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities2007-05-02
Bugzilla
CVE-2007-1321 xen QEMU NE2000 emulation issues2007-04-20
CVE-2007-1321 (HIGH CVSS 7.2) | Integer signedness error in the NE2 | cvebase.io