Wind River Support Network

HomeOther DownloadsThe patch comes from qemu 0.9.1 to fix CVE-2007-1321
Recommended Type: Patch

The patch comes from qemu 0.9.1 to fix CVE-2007-1321

Released: Jul 2, 2008     Updated: Jul 2, 2008

Description

Integer signedness error in the NE2000 emulator in QEMU 0.8.2, as used in Xen and possibly other products, allows local users to trigger a heap-based buffer overflow via certain register values that bypass sanity checks, aka QEMU NE2000 "receive" integer signedness error. NOTE: this identifier was inadvertently used by some sources to cover multiple issues that were labeled "NE2000 network driver and the socket code," but separate identifiers have been created for the individual vulnerabilities since there are sometimes different fixes; see CVE-2007-5729 and CVE-2007-5730.

http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-1321 IDENTIFIER = WIND00118334


Product Version

Linux Platforms 2.0, Linux Platforms 1.x

Downloads


Installation Notes

Installation Notes

WIND00125248.zip for 1.4
WIND00125249.zip for 1.5

1. Unzip the patch under [install_dir]/updates

2. Install the patch CD by entering the patch CD directory and run setup_linux.

3. This is a source only patch so you will have to build the kernel

4. Issue a make fs and make the kernel in a configured directory.

5. Upload the kernel and rootfs into the target and boot it up.


Live chat
Online