First published: Tue Oct 14 2008(Updated: )
Created <span class=""><a href="attachment.cgi?id=320281&action=diff" name="attach_320281" title="Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (CVE-2007-1320)">attachment 320281</a> <a href="attachment.cgi?id=320281&action=edit" title="Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (CVE-2007-1320)">[details]</a></span> Proposed actualized upstream qemu patch to resolve the Cirrus LGD-54XX "bitblt" heap overflow (<a href="https://access.redhat.com/security/cve/CVE-2007-1320">CVE-2007-1320</a>) Jan Niehusmann discovered that the upstream fix for the <a href="https://access.redhat.com/security/cve/CVE-2007-1320">CVE-2007-1320</a> is incomplete and still allows local users to cause a heap-based buffer overlow, when connecting via the VNC console. Steps to reproduce: No reproducer. Upstream qemu patch for the initial <a href="https://access.redhat.com/security/cve/CVE-2007-1320">CVE-2007-1320</a> issue: <a href="https://svn.pardus.org.tr/pardus/2007/applications/emulators/qemu/files/CVE-2007-1320.patch">https://svn.pardus.org.tr/pardus/2007/applications/emulators/qemu/files/CVE-2007-1320.patch</a> Proposed upstream correction of this patch - see attachment.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Canonical Ubuntu Linux | =8.10 | |
Canonical Ubuntu Linux | =8.04 | |
Debian Debian Linux | =5.0 | |
Debian Debian Linux | =4.0 | |
Kvm Qumranet Kvm | <=81 | |
QEMU qemu | <0.10.0 | |
Canonical Ubuntu Linux | ||
Debian Debian Linux |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.