QEMU net socket buffer overflow

qemu-net-socket-bo (38239) The risk level is classified as HighHigh Risk

Description:

QEMU is vulnerable to a heap-based buffer overflow. By sending specially-crafted data in the "net socket listen" option, a local attacker could overflow a buffer and execute arbitrary code on the system.

Platforms Affected:

  • Fabrice Bellard, QEMU 0.8.2
  • MandrakeSoft, Mandrake Linux 2007 X86_64
  • MandrakeSoft, Mandrake Linux 2007
  • MandrakeSoft, Mandrake Linux 2007.1
  • MandrakeSoft, Mandrake Linux 2007.1 X86_64
  • MandrakeSoft, Mandrake Linux Corporate Server 4.0
  • MandrakeSoft, Mandrake Linux Corporate Server 4.0 X86_64
  • RedHat, Enterprise Linux 5 Client
  • RedHat, Enterprise Linux 5
  • RedHat, RHEL Desktop Multi OS 5 Client
  • RedHat, RHEL Virtualization 5 Server

Remedy:

Contact your vendor for upgrade or patch information. See References.

Consequences:

Gain Access

References:

  • QEMU Web site, QEMU at http://fabrice.bellard.free.fr/qemu/.
  • BID-23731: QEMU Multiple Local Vulnerabilities
  • CVE-2007-5730: Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the net socket listen option, aka QEMU net socket heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of NE2000 network driver and the socket code
  • FrSIRT/ADV-2007-1597: QEMU Data Handling Multiple Command Execution and Denial of Service Vulnerabilities
  • MDKSA-2007:203: Updated xen packages fix multiple vulnerabilities
  • RHSA-2008-0194: Important: xen security and bug fix update
  • SA25073: QEMU Various Vulnerabilities

Reported:

Nov 01, 2007

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page