CVE-2007-1321

high

Description

Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.

References

https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00082.html

https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00030.html

https://www.redhat.com/archives/fedora-package-announce/2007-November/msg00004.html

https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9302

http://www.vupen.com/english/advisories/2007/1597

http://www.securityfocus.com/bid/23731

http://www.redhat.com/support/errata/RHSA-2007-0323.html

http://www.mandriva.com/security/advisories?name=MDVSA-2008:162

http://www.mandriva.com/security/advisories?name=MDKSA-2007:203

http://www.debian.org/security/2007/dsa-1284

http://www.attrition.org/pipermail/vim/2007-October/001842.html

http://taviso.decsystem.org/virtsec.pdf

http://securitytracker.com/id?1018761

http://secunia.com/advisories/29129

http://secunia.com/advisories/27486

http://secunia.com/advisories/27103

http://secunia.com/advisories/27072

http://secunia.com/advisories/27047

http://secunia.com/advisories/25095

http://secunia.com/advisories/25073

Details

Source: Mitre, NVD

Published: 2007-10-30

Updated: 2020-12-15

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High