Vulnerability Name: | CVE-2007-2893 (CCN-34508) | ||||||||||||||||
Assigned: | 2007-05-01 | ||||||||||||||||
Published: | 2007-05-01 | ||||||||||||||||
Updated: | 2020-05-19 | ||||||||||||||||
Summary: | Heap-based buffer overflow in the bx_ne2k_c::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system via vectors that cause TXCNT register values to exceed the device memory size, aka "RX Frame heap overflow." | ||||||||||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C) 5.3 Medium (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||
Vulnerability Type: | CWE-119 | ||||||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||||||
References: | Source: CCN Type: boch's Web site bochs: The Open Source IA-31 Emulation Project (Home Page) Source: CONFIRM Type: Third Party Advisory http://bugs.gentoo.org/show_bug.cgi?id=188148 Source: MITRE Type: CNA CVE-2007-2893 Source: OSVDB Type: Broken Link 36799 Source: CCN Type: SA25470 Bochs NE2000 RX Frame Overflow and Disk Controller Denial of Service Source: SECUNIA Type: Third Party Advisory 25470 Source: SECUNIA Type: Third Party Advisory 26364 Source: SECUNIA Type: Third Party Advisory 27715 Source: GENTOO Type: Third Party Advisory GLSA-200711-21 Source: CCN Type: Tavis Ormandy White paper An Empirical Study into the Security Exposures to Hosts of Hostile Virtualized Environments Source: MISC Type: Third Party Advisory http://taviso.decsystem.org/virtsec.pdf Source: DEBIAN Type: Third Party Advisory DSA-1351 Source: DEBIAN Type: DSA-1351 bochs -- buffer overflow Source: CCN Type: GLSA-200711-21 Bochs: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 35497 QEMU NE2000 Device Registers Integer Signedness Error Source: CCN Type: OSVDB ID: 36799 Bochs NE2000 iodev/ne2k.cc bx_ne2k_c::rx_frame Function Local Overflow Source: BID Type: Third Party Advisory, VDB Entry 24246 Source: CCN Type: BID-24246 Bochs Buffer Overflow and Denial Of Service Vulnerabilities Source: VUPEN Type: Third Party Advisory ADV-2007-1936 Source: XF Type: Third Party Advisory, VDB Entry bochs-ne2000-bo(34508) Source: XF Type: UNKNOWN bochs-ne2000-bo(34508) | ||||||||||||||||
Vulnerable Configuration: | Configuration 1:![]() | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |