CVE-2007-2893

Source
https://nvd.nist.gov/vuln/detail/CVE-2007-2893
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2007-2893.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2007-2893
Related
Published
2007-05-30T01:30:00Z
Modified
2024-11-21T00:31:54Z
Summary
[none]
Details

Heap-based buffer overflow in the bxne2kc::rx_frame function in iodev/ne2k.cc in the emulated NE2000 device in Bochs 2.3 allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system via vectors that cause TXCNT register values to exceed the device memory size, aka "RX Frame heap overflow."

References

Affected packages

Debian:11 / bochs

Package

Name
bochs
Purl
pkg:deb/debian/bochs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3+20070705-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:12 / bochs

Package

Name
bochs
Purl
pkg:deb/debian/bochs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3+20070705-1

Ecosystem specific

{
    "urgency": "low"
}

Debian:13 / bochs

Package

Name
bochs
Purl
pkg:deb/debian/bochs?arch=source

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.3+20070705-1

Ecosystem specific

{
    "urgency": "low"
}