7.2
CVSSv2

CVE-2007-1320

Published: 02/05/2007 Updated: 15/12/2020
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

qemu qemu 0.8.2

fedoraproject fedora 8

fedoraproject fedora 9

fedoraproject fedora core 6

opensuse opensuse 11.0

opensuse opensuse 11.1

debian debian linux 3.1

debian debian linux 4.0

Vendor Advisories

Debian Bug report logs - #481204 kvm: CVE-2008-2004 allows unauthorized disclosure of information Package: kvm; Maintainer for kvm is (unknown); Reported by: Nico Golde <nion@debianorg> Date: Wed, 14 May 2008 14:12:01 UTC Severity: grave Tags: patch, security Fixed in version kvm/66+dfsg-11 Done: Steffen Joeris <whi ...
Debian Bug report logs - #526040 qemu: CVE-2008-4539 buffer overlflow vulnerability Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: "Michael S Gilbert" <michaelsgilbert@gmailcom> Date: Tue, 28 Apr 2009 ...
Debian Bug report logs - #424070 security issues not fixed in qemu in unstable Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: Stefan Fritsch <sf@sfritschde> Date: Tue, 15 May 2007 16:48:01 UTC Severity: ...
Debian Bug report logs - #469649 qemu: CVE-2008-0928 privilege escalation Package: qemu; Maintainer for qemu is Debian QEMU Team <pkg-qemu-devel@listsaliothdebianorg>; Source for qemu is src:qemu (PTS, buildd, popcon) Reported by: Nico Golde <nion@debianorg> Date: Thu, 6 Mar 2008 11:18:04 UTC Severity: importan ...
Several vulnerabilities have been discovered in the QEMU processor emulator, which may lead to the execution of arbitrary code or denial of service The Common Vulnerabilities and Exposures project identifies the following problems: CVE-2007-1320 Tavis Ormandy discovered that a memory management routine of the Cirrus video driver performs ...