CVE-2007-1366

QEMU 0.8.2 - Denial of Service via AAM Instruction Divisor Operand

Title source: llm
STIX 2.1

Description

QEMU 0.8.2 allows local users to crash a virtual machine via the divisor operand to the aam instruction, as demonstrated by "aam 0x0," which triggers a divide-by-zero error.

References (12)

Core 12
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/23731
Third Party Advisory vendor-advisory x_refsource_debian
http://www.debian.org/security/2007/dsa-1284
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25073
Technical Description, Third Party Advisory x_refsource_misc
http://taviso.decsystem.org/virtsec.pdf
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00650.html
Third Party Advisory vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2008:162
Broken Link vdb-entry x_refsource_osvdb
http://osvdb.org/35498
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2007/1597
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29129
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/25095
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/34046
Mailing List, Patch, Third Party Advisory mailing-list x_refsource_mlist
http://lists.gnu.org/archive/html/qemu-devel/2007-04/msg00651.html

Scores

EPSS 0.0006
EPSS Percentile 20.0%

Details

Status published
Products (3)
debian/debian_linux 3.1
debian/debian_linux 4.0
qemu/qemu 0.8.2
Published May 02, 2007
Tracked Since Feb 18, 2026