CVE-2007-1366: Low severity Qemu Qemu vulnerability
Published May 2, 2007
·Updated
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
Affected Software
3 affected components
Qemu Qemu=0.8.2
Debian Debian Linux=3.1
Debian Debian Linux=4.0
Remediation
Event History
May 2, 2007
CVE Published
05:19 PM
CVE Published
via MITRE·09:00 PM
Data Sourced
via MITRE·09:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1366?
CVE-2007-1366 has a high severity rating due to its ability to crash a virtual machine.
2
How do I fix CVE-2007-1366?
To resolve CVE-2007-1366, upgrade to a version of QEMU that is newer than 0.8.2.
3
What systems are affected by CVE-2007-1366?
CVE-2007-1366 affects QEMU version 0.8.2 and specific versions of Debian GNU/Linux.
4
Can CVE-2007-1366 be exploited remotely?
CVE-2007-1366 requires local access to the virtual machine to exploit.
5
What is the nature of the vulnerability in CVE-2007-1366?
CVE-2007-1366 is a vulnerability caused by a divide-by-zero error triggered by the aam instruction.