HIGH · 7.2

CVE-2007-1320

Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute ...

Vulnerability Description

Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
QemuQemu0.8.2
XenXen-
FedoraprojectFedora8
FedoraprojectFedora Core6
OpensuseOpensuse11.0
DebianDebian Linux3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-1320?

CVE-2007-1320 is a vulnerability with a CVSS score of 7.2 (HIGH). Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute ...

How severe is CVE-2007-1320?

CVE-2007-1320 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-1320?

Check the references section above for vendor advisories and patch information. Affected products include: Qemu Qemu, Xen Xen, Fedoraproject Fedora, Fedoraproject Fedora Core, Opensuse Opensuse.