VDB
CVE-2007-5730
CVE-2007-5730
PUBLISHED
Reported by mitre · Published October 30, 2007
Heap-based buffer overflow in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to execute arbitrary code via crafted data in the "net socket listen" option, aka QEMU "net socket" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the individual net socket listen vulnerability.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a, n/a |
Timeline
- Oct 30, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 23731 vdb-entryx_refsource_BID
- MDKSA-2007:203 vendor-advisoryx_refsource_MANDRIVA
- RHSA-2008:0194 vendor-advisoryx_refsource_REDHAT
- qemu-net-socket-bo(38239) vdb-entryx_refsource_XF
- 42985 vdb-entryx_refsource_OSVDB
- DSA-1284 vendor-advisoryx_refsource_DEBIAN
- 25073 third-party-advisoryx_refsource_SECUNIA
- x_refsource_MISC
- 27486 third-party-advisoryx_refsource_SECUNIA
- MDVSA-2008:162 vendor-advisoryx_refsource_MANDRIVA
- oval:org.mitre.oval:def:10000 vdb-entrysignaturex_refsource_OVAL
- 29963 third-party-advisoryx_refsource_SECUNIA
- ADV-2007-1597 vdb-entryx_refsource_VUPEN
- 29129 third-party-advisoryx_refsource_SECUNIA
- 25095 third-party-advisoryx_refsource_SECUNIA
- 20071030 Clarification on old QEMU/NE2000/Xen issues mailing-listx_refsource_VIM