QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.
References
Link | Resource |
---|---|
http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00650.html | Mailing List Third Party Advisory |
http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00651.html | Mailing List Patch Third Party Advisory |
http://taviso.decsystem.org/virtsec.pdf | Technical Description Third Party Advisory |
http://www.debian.org/security/2007/dsa-1284 | Third Party Advisory |
http://www.securityfocus.com/bid/23731 | Third Party Advisory VDB Entry |
http://secunia.com/advisories/25073 | Third Party Advisory |
http://secunia.com/advisories/25095 | Third Party Advisory |
http://www.mandriva.com/security/advisories?name=MDVSA-2008:162 | Third Party Advisory |
http://secunia.com/advisories/29129 | Third Party Advisory |
http://www.vupen.com/english/advisories/2007/1597 | Third Party Advisory |
http://osvdb.org/35498 | Broken Link |
https://exchange.xforce.ibmcloud.com/vulnerabilities/34046 | Third Party Advisory VDB Entry |
Information
Published : 2007-05-02 10:19
Updated : 2020-12-15 15:49
NVD link : CVE-2007-1366
Mitre link : CVE-2007-1366
JSON object : View
CWE
Products Affected
debian
- debian_linux
qemu
- qemu