Bugtraq mailing list archives

[ GLSA 200711-21 ] Bochs: Multiple vulnerabilities


From: Pierre-Yves Rofes <py () gentoo org>
Date: Sun, 18 Nov 2007 00:58:21 +0100

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory                           GLSA 200711-21
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
                                            http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

  Severity: High
     Title: Bochs: Multiple vulnerabilities
      Date: November 17, 2007
      Bugs: #188148
        ID: 200711-21

- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Synopsis
========

Multiple vulnerabilities have been discovered in Bochs, possibly
allowing for the execution of arbitrary code or a Denial of Service.

Background
==========

Bochs is a IA-32 (x86) PC emulator written in C++.

Affected packages
=================

    -------------------------------------------------------------------
     Package              /  Vulnerable  /                  Unaffected
    -------------------------------------------------------------------
  1  app-emulation/bochs        < 2.3                           >= 2.3

Description
===========

Tavis Ormandy of the Google Security Team discovered a heap-based
overflow vulnerability in the NE2000 driver (CVE-2007-2893). He also
discovered a divide-by-zero error in the emulated floppy disk
controller (CVE-2007-2894).

Impact
======

A local attacker in the guest operating system could exploit these
issues to execute code outside of the virtual machine, or cause Bochs
to crash.

Workaround
==========

There is no known workaround at this time.

Resolution
==========

All Bochs users should upgrade to the latest version:

    # emerge --sync
    # emerge --ask --oneshot --verbose ">=app-emulation/bochs-2.3"

References
==========

  [ 1 ] CVE-2007-2893
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2893
  [ 2 ] CVE-2007-2894
        http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2894

Availability
============

This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:

  http://security.gentoo.org/glsa/glsa-200711-21.xml

Concerns?
=========

Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security () gentoo org or alternatively, you may file a bug at
http://bugs.gentoo.org.

License
=======

Copyright 2007 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).

The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.

http://creativecommons.org/licenses/by-sa/2.5
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.7 (GNU/Linux)
Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org

iD8DBQFHP4AduhJ+ozIKI5gRAoGsAJ9eTHVtsnVWsAII4m9eSnmobPGyLQCfcQqf
ktlcEcQo/3p6PbW4BrKZlxI=
=lCTl
-----END PGP SIGNATURE-----


Current thread: