DEBIAN-CVE-2007-5729

Advisory lineage Upstream: 1 Downstream: 1
Upstream
Downstream
Published: 30 Oct 2007, 22:46
Last modified:28 Apr 2026, 20:09

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

30 Oct 2007, 22:46
Published
Vulnerability first disclosed
28 Apr 2026, 20:09
Last Modified
Vulnerability information updated

Description

The NE2000 emulator in QEMU 0.8.2 allows local users to execute arbitrary code by writing Ethernet frames with a size larger than the MTU to the EN0_TCNT register, which triggers a heap-based buffer overflow in the slirp library, aka NE2000 "mtu" heap overflow. NOTE: some sources have used CVE-2007-1321 to refer to this issue as part of "NE2000 network driver and the socket code," but this is the correct identifier for the mtu overflow vulnerability.

Affected Systems

  • debianqemu

    < 0.9.0-2 | < 0.9.0-2 | < 0.9.0-2 | < 0.9.0-2

References (1)