PT-2007-1011 · Bochs · Bochs

Published

2007-05-30

·

Updated

2020-05-19

·

CVE-2007-2893

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Bochs version 2.3
Description: The issue allows local users of the guest operating system to write to arbitrary memory locations and gain privileges on the host operating system. This is due to a heap-based buffer overflow in the emulated NE2000 device. The overflow occurs in the bx ne2k c::rx frame function when TXCNT register values exceed the device memory size. Additionally, there are multiple vulnerabilities in the sb16ctrl-bochs package that can lead to breaches of confidentiality, integrity, and availability of protected information, which can be exploited by a local attacker.
Recommendations: For Bochs version 2.3, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider disabling the bx ne2k c::rx frame function until a patch is available. Restrict access to the emulated NE2000 device to minimize the risk of exploitation. Avoid using the TXCNT register in a way that could cause its values to exceed the device memory size until the issue is resolved.

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-02051
CVE-2007-2893
DSA-1351-1

Affected Products

Bochs