CVE-2007-2893

Heap-based buffer overflow in the bx_ne2k_c::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system via vectors that cause TXCNT register values to exceed the device memory size, aka "RX Frame heap overflow."
Configurations

Configuration 1 (hide)

cpe:2.3:a:bochs_project:bochs:2.3:-:*:*:*:*:*:*

History

21 Nov 2024, 00:31

Type Values Removed Values Added
References () http://bugs.gentoo.org/show_bug.cgi?id=188148 - Third Party Advisory () http://bugs.gentoo.org/show_bug.cgi?id=188148 - Third Party Advisory
References () http://osvdb.org/36799 - Broken Link () http://osvdb.org/36799 - Broken Link
References () http://secunia.com/advisories/25470 - Third Party Advisory () http://secunia.com/advisories/25470 - Third Party Advisory
References () http://secunia.com/advisories/26364 - Third Party Advisory () http://secunia.com/advisories/26364 - Third Party Advisory
References () http://secunia.com/advisories/27715 - Third Party Advisory () http://secunia.com/advisories/27715 - Third Party Advisory
References () http://security.gentoo.org/glsa/glsa-200711-21.xml - Third Party Advisory () http://security.gentoo.org/glsa/glsa-200711-21.xml - Third Party Advisory
References () http://taviso.decsystem.org/virtsec.pdf - Third Party Advisory () http://taviso.decsystem.org/virtsec.pdf - Third Party Advisory
References () http://www.debian.org/security/2007/dsa-1351 - Third Party Advisory () http://www.debian.org/security/2007/dsa-1351 - Third Party Advisory
References () http://www.securityfocus.com/bid/24246 - Third Party Advisory, VDB Entry () http://www.securityfocus.com/bid/24246 - Third Party Advisory, VDB Entry
References () http://www.vupen.com/english/advisories/2007/1936 - Third Party Advisory () http://www.vupen.com/english/advisories/2007/1936 - Third Party Advisory
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/34508 - Third Party Advisory, VDB Entry () https://exchange.xforce.ibmcloud.com/vulnerabilities/34508 - Third Party Advisory, VDB Entry

Information

Published : 2007-05-30 01:30

Updated : 2024-11-21 00:31


NVD link : CVE-2007-2893

Mitre link : CVE-2007-2893

CVE.ORG link : CVE-2007-2893


JSON object : View

Products Affected

bochs_project

  • bochs
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer