[Forgot Password]
Login  Register Subscribe

23631

 
 

115038

 
 

96174

 
 

909

 
 

78077

 
 

109

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML

CVE-2007-2893

Date: (C)2007-05-29   (M)2017-07-31
 
CVSS Score: 7.2Access Vector: LOCAL
Exploitability Subscore: 3.9Access Complexity: LOW
Impact Subscore: 10.0Authentication: NONE
 Confidentiality: COMPLETE
 Integrity: COMPLETE
 Availability: COMPLETE











Heap-based buffer overflow in the bx_ne2k_c::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system via vectors that cause TXCNT register values to exceed the device memory size, aka "RX Frame heap overflow."

Reference:
BID-24246
SECUNIA-25470
SECUNIA-26364
SECUNIA-27715
OSVDB-36799
ADV-2007-1936
DSA-1351
GLSA-200711-21
bochs-ne2000-bo(34508)
http://bugs.gentoo.org/show_bug.cgi?id=188148
http://taviso.decsystem.org/virtsec.pdf

CWE    1
CWE-119

© 2013 SecPod Technologies