Description
Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-1284-1 | New qemu packages fix several vulnerabilities |
Debian DSA |
DSA-1384-1 | New xen-utils packages fix several vulnerabilities |
EUVD |
EUVD-2007-1317 | Multiple heap-based buffer overflows in the cirrus_invalidate_region function in the Cirrus VGA extension in QEMU 0.8.2, as used in Xen and possibly other products, might allow local users to execute arbitrary code via unspecified vectors related to "attempting to mark non-existent regions as dirty," aka the "bitblt" heap overflow. |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-07T12:50:35.128Z
Reserved: 2007-03-07T00:00:00.000Z
Link: CVE-2007-1320
No data.
Status : Deferred
Published: 2007-05-02T17:19:00.000
Modified: 2025-04-09T00:30:58.490
Link: CVE-2007-1320
OpenCVE Enrichment
No data.
Weaknesses
Debian DSA
EUVD