CVE-2007-1321
Last modified
CVE-2007-1321 is a vulnerability of currently unknown severity. Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.. EPSS estimates a 0.46% chance of exploitation in the next 30 days.
Description
Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Qemu | Qemu | 0.8.2 |
| Fedoraproject | Fedora | 7 |
| Fedoraproject | Fedora Core | 6 |
| Debian | Debian Linux | 3.1 |
| Debian | Debian Linux | 4.0 |
References
- http://osvdb.org/35495Broken Link
- http://secunia.com/advisories/25073Third Party Advisory
- http://secunia.com/advisories/25095Third Party Advisory
- http://secunia.com/advisories/27047Third Party Advisory
- http://secunia.com/advisories/27072Third Party Advisory
- http://secunia.com/advisories/27103Third Party Advisory
- http://secunia.com/advisories/27486Third Party Advisory
- http://secunia.com/advisories/29129Third Party Advisory
- http://securitytracker.com/id?1018761Third Party Advisory, VDB Entry
- http://taviso.decsystem.org/virtsec.pdfTechnical Description, Third Party Advisory
- http://www.attrition.org/pipermail/vim/2007-October/001842.htmlThird Party Advisory
- http://www.debian.org/security/2007/dsa-1284Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:203Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:162Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0323.htmlThird Party Advisory
- http://www.securityfocus.com/bid/23731Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/1597Third Party Advisory
- http://osvdb.org/35495Broken Link
- http://secunia.com/advisories/25073Third Party Advisory
- http://secunia.com/advisories/25095Third Party Advisory
- http://secunia.com/advisories/27047Third Party Advisory
- http://secunia.com/advisories/27072Third Party Advisory
- http://secunia.com/advisories/27103Third Party Advisory
- http://secunia.com/advisories/27486Third Party Advisory
- http://secunia.com/advisories/29129Third Party Advisory
- http://securitytracker.com/id?1018761Third Party Advisory, VDB Entry
- http://taviso.decsystem.org/virtsec.pdfTechnical Description, Third Party Advisory
- http://www.attrition.org/pipermail/vim/2007-October/001842.htmlThird Party Advisory
- http://www.debian.org/security/2007/dsa-1284Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDKSA-2007:203Third Party Advisory
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:162Third Party Advisory
- http://www.redhat.com/support/errata/RHSA-2007-0323.htmlThird Party Advisory
- http://www.securityfocus.com/bid/23731Third Party Advisory, VDB Entry
- http://www.vupen.com/english/advisories/2007/1597Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-1321?
How severe is CVE-2007-1321?
How do I fix CVE-2007-1321?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-1307Unspecified vulnerability in Lenovo Intel PRO/1000 LAN adapt…
- CVE-2007-1308ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konque…
- CVE-2007-1309Novell Access Management 3 SSLVPN Server allows remote authe…
- CVE-2007-1313NETxAutomation NETxEIB OPC Server before 3.0.1300 does not p…
- CVE-2007-1319Unspecified vulnerability in the IOPCServer::RemoveGroup fun…
- CVE-2007-1320Multiple heap-based buffer overflows in the cirrus_invalidat…
- CVE-2007-1322QEMU 0.8.2 allows local users to halt a virtual machine by e…
- CVE-2007-1323Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultI…
- CVE-2007-1324SnapGear 560, 585, 580, 640, 710, and 720 appliances before …
- CVE-2007-1325The PMA_ArrayWalkRecursive function in libraries/common.lib.…
- CVE-2007-1326SQL injection vulnerability in index.php in Serendipity 1.1.…
- CVE-2007-1327The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in…
Are you affected by CVE-2007-1321?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
