CVE-2007-1321 - CVE House
Back to Database
Status published High CVE-2007-1321

Integer signedness error in the NE2000 emulator in QEMU 0.8.2,...

Vulnerability Description

Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2007-1321

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

qemu, fedora, fedora core, debian linux
Vulnerable Versions:
0.8.2, 7, 6, 3.1, 4.0

Timeline

Official Publish: October 30th, 2007
Last Modified: August 7th, 2024
Added to House: July 18th, 2026

CVSS Vectors

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.