CVE-2007-1366
published 2007-05-02CVE-2007-1366: QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNINAP
EPSS
0.40%
32.5th percentile
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 0.9.0-2 (bookworm) | qemu 0.9.0-2 (bookworm) |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
xen aam instruction crash
vendor_redhat·2007-04-20·CVSS 2.1
CVE-2007-1366 [LOW] xen aam instruction crash
xen aam instruction crash
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
Statement: Not vulnerable. This issue did not affect Xen as shipped with Red Hat Enterprise Linux 5.
Debian
CVE-2007-1366: qemu - QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand...
vendor_debian·2007·CVSS 2.1
CVE-2007-1366 [LOW] CVE-2007-1366: qemu - QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand...
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
GHSA
GHSA-p6fx-39vq-68cw: QEMU 0
ghsa_unreviewed·2022-05-01
CVE-2007-1366 [LOW] GHSA-p6fx-39vq-68cw: QEMU 0
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
OSV
CVE-2007-1366: QEMU 0
osv·2007-05-02·CVSS 2.1
CVE-2007-1366 [LOW] CVE-2007-1366: QEMU 0
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
No detection rules found.
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
bugzilla·2007-09-26·CVSS 7.2
CVE-2007-1366 [HIGH] CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
+++ This bug was initially created as a clone of Bug #238723 +++
Not sure if these affect any qemu versions in Fedora, but here goes:
http://www.vuxml.org/freebsd/0ac89b39-f829-11db-b55c-000e0c6d38a9.html
"Several vulnerabilities have been discovered in the QEMU processor emulator,
which may lead to the execution of arbitrary code or denial of service. The
Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video
driver performs insufficient bounds checking, which might allow the execution of
arbitrary code through a heap overflow.
CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the
Bugzilla
CVE-2007-1366 xen aam instruction crash
bugzilla·2007-09-19·CVSS 2.1
CVE-2007-1366 [LOW] CVE-2007-1366 xen aam instruction crash
CVE-2007-1366 xen aam instruction crash
Tavis Ormandy discovered that the aam instruction can be
abused to crash qemu through a division by zero, resulting in
denial of service.
public via http://taviso.decsystem.org/virtsec.pdf
also see http://lists.xensource.com/archives/html/xen-devel/2007-05/msg00021.html
Discussion:
Not vulnerable. This issue did not affect Xen as shipped with Red Hat Enterprise
Linux 5.
Bugzilla
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
bugzilla·2007-05-02·CVSS 7.2
CVE-2007-1366 [HIGH] CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
CVE-2007-13{20-23}, CVE-2007-1366: qemu multiple vulnerabilities
Not sure if these affect any qemu versions in Fedora, but here goes:
http://www.vuxml.org/freebsd/0ac89b39-f829-11db-b55c-000e0c6d38a9.html
"Several vulnerabilities have been discovered in the QEMU processor emulator,
which may lead to the execution of arbitrary code or denial of service. The
Common Vulnerabilities and Exposures project identifies the following problems:
CVE-2007-1320
Tavis Ormandy discovered that a memory management routine of the Cirrus video
driver performs insufficient bounds checking, which might allow the execution of
arbitrary code through a heap overflow.
CVE-2007-1321
Tavis Ormandy discovered that the NE2000 network driver and the socket code
perform insufficient input validation, which might al
http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00650.htmlhttp://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00651.htmlhttp://osvdb.org/35498http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/29129http://taviso.decsystem.org/virtsec.pdfhttp://www.debian.org/security/2007/dsa-1284http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://exchange.xforce.ibmcloud.com/vulnerabilities/34046http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00650.htmlhttp://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00651.htmlhttp://osvdb.org/35498http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/29129http://taviso.decsystem.org/virtsec.pdfhttp://www.debian.org/security/2007/dsa-1284http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://exchange.xforce.ibmcloud.com/vulnerabilities/34046
2007-05-02
Published