First published: Fri Aug 08 2008(Updated: )
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Linux kernel | =2.6.27-rc1 | |
Linux Linux kernel | <2.6.27 | |
Linux Linux kernel | =2.6.27 | |
Debian Debian Linux | =4.0 | |
Canonical Ubuntu Linux | =6.06 | |
Canonical Ubuntu Linux | =7.04 | |
Canonical Ubuntu Linux | =7.10 | |
Canonical Ubuntu Linux | =8.04 | |
Redhat Enterprise Linux Desktop | =4.0 | |
Redhat Enterprise Linux Eus | =4.7 | |
Redhat Enterprise Linux Server | =4.0 | |
Redhat Enterprise Linux Workstation | =4.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.