First published: Wed May 02 2007(Updated: )
QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QEMU | =0.8.2 | |
Debian Linux | =3.1 | |
Debian Linux | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1366 has a high severity rating due to its ability to crash a virtual machine.
To resolve CVE-2007-1366, upgrade to a version of QEMU that is newer than 0.8.2.
CVE-2007-1366 affects QEMU version 0.8.2 and specific versions of Debian GNU/Linux.
CVE-2007-1366 requires local access to the virtual machine to exploit.
CVE-2007-1366 is a vulnerability caused by a divide-by-zero error triggered by the aam instruction.