CVE-2007-5729
published 2007-10-30CVE-2007-5729: The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT…
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.58%
44.4th percentile
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | qemu | < qemu 0.9.0-2 (bookworm) | qemu 0.9.0-2 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora_core | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| qemu | qemu | — | — |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
| qemu | qemu | >= 0 < 0.9.0-2 | 0.9.0-2 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-793p-rv2q-qv42: Integer signedness error in the NE2000 emulator in QEMU 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-1321 [HIGH] GHSA-793p-rv2q-qv42: Integer signedness error in the NE2000 emulator in QEMU 0
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
GHSA
GHSA-pqgp-87m3-3238: The NE2000 emulator in QEMU 0
ghsa_unreviewed·2022-05-01·CVSS 7.2
CVE-2007-5729 [HIGH] CWE-119 GHSA-pqgp-87m3-3238: The NE2000 emulator in QEMU 0
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
OSV
CVE-2007-5729: The NE2000 emulator in QEMU 0
osv·2007-10-30·CVSS 7.2
CVE-2007-5729 [HIGH] CVE-2007-5729: The NE2000 emulator in QEMU 0
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
OSV
CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0
osv·2007-10-30·CVSS 7.2
CVE-2007-1321 [HIGH] CVE-2007-1321: Integer signedness error in the NE2000 emulator in QEMU 0
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Red Hat
QEMU Buffer overflow via crafted "net socket listen" option
vendor_redhat·2007-10-23·CVSS 7.2
CVE-2007-5730 [HIGH] QEMU Buffer overflow via crafted "net socket listen" option
QEMU Buffer overflow via crafted "net socket listen" option
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
Statement: Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5729
The Red Hat Product Security has rated this issue as having low security impact, a future update may address this flaw.
Red Hat
xen QEMU NE2000 emulation issues
vendor_redhat·2007-04-20·CVSS 7.2
CVE-2007-1321 [HIGH] xen QEMU NE2000 emulation issues
xen QEMU NE2000 emulation issues
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Debian
CVE-2007-1321: qemu - Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen an...
vendor_debian·2007·CVSS 7.2
CVE-2007-1321 [HIGH] CVE-2007-1321: qemu - Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen an...
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
Debian
CVE-2007-5729: qemu - The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code b...
vendor_debian·2007·CVSS 7.2
CVE-2007-5729 [HIGH] CVE-2007-5729: qemu - The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code b...
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
Scope: local
bookworm: resolved (fixed in 0.9.0-2)
bullseye: resolved (fixed in 0.9.0-2)
forky: resolved (fixed in 0.9.0-2)
sid: resolved (fixed in 0.9.0-2)
trixie: resolved (fixed in 0.9.0-2)
Red Hat
QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
vendor_redhat·CVSS 7.2
CVE-2007-5729 [HIGH] QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
QEMU NE2000 Buffer overflow triggerable by frames larger than MTU
The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.
Statement: Not vulnerable. This issue did not affect Xen as shipped with Red Hat Enterprise Linux 5.
Red Hat is aware of this issue and is tracking it via the following bug: https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=CVE-2007-5729
The Red Hat Product Security has rat
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://osvdb.org/42986http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/27486http://secunia.com/advisories/29129http://secunia.com/advisories/33568http://taviso.decsystem.org/virtsec.pdfhttp://www.attrition.org/pipermail/vim/2007-October/001842.htmlhttp://www.debian.org/security/2007/dsa-1284http://www.mandriva.com/security/advisories?name=MDKSA-2007:203http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://exchange.xforce.ibmcloud.com/vulnerabilities/38238http://lists.opensuse.org/opensuse-security-announce/2009-01/msg00004.htmlhttp://osvdb.org/42986http://secunia.com/advisories/25073http://secunia.com/advisories/25095http://secunia.com/advisories/27486http://secunia.com/advisories/29129http://secunia.com/advisories/33568http://taviso.decsystem.org/virtsec.pdfhttp://www.attrition.org/pipermail/vim/2007-October/001842.htmlhttp://www.debian.org/security/2007/dsa-1284http://www.mandriva.com/security/advisories?name=MDKSA-2007:203http://www.mandriva.com/security/advisories?name=MDVSA-2008:162http://www.securityfocus.com/bid/23731http://www.vupen.com/english/advisories/2007/1597https://exchange.xforce.ibmcloud.com/vulnerabilities/38238
2007-10-30
Published