PT-2008-6906 · Linux+1 · Linux Kernel+1

·

CVE-2008-3272

·

Publicado

1970-01-01

·

Atualizado

2023-02-13

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions linux-headers-2.6.24-etchnhalf.1-all-mips versions linux-headers-2.6.24-etchnhalf.1-r4k-ip22 versions linux-headers-2.6.24-etchnhalf.1-r5k-ip32 versions linux-image-2.6.24-etchnhalf.1-r4k-ip22 versions linux-image-2.6.24-etchnhalf.1-r5k-ip32 versions kernel-rt debug-debuginfo versions kernel-rt debug-debugsource versions kernel-rt-debuginfo versions kernel-rt-debugsource versions Linux kernel versions prior to 2.6.27-rc2
Description The issue involves multiple vulnerabilities in various Linux kernel and operating system packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The snd seq oss synth make info function in the sound subsystem of the Linux kernel does not verify that the device number is within the defined range before returning certain data to the caller, allowing local users to obtain sensitive information.
Recommendations For linux-headers-2.6.24-etchnhalf.1-all-mips, update to a version that includes the necessary security patches. For linux-headers-2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches. For linux-headers-2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches. For linux-image-2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches. For linux-image-2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches. For kernel-rt debug-debuginfo, update to a version that includes the necessary security patches. For kernel-rt debug-debugsource, update to a version that includes the necessary security patches. For kernel-rt-debuginfo, update to a version that includes the necessary security patches. For kernel-rt-debugsource, update to a version that includes the necessary security patches. For Linux kernel versions prior to 2.6.27-rc2, update to version 2.6.27-rc2 or later to address the vulnerability in the snd seq oss synth make info function.

Correção

Buffer Overflow

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-02636
BDU:2015-02637
BDU:2015-02638
BDU:2015-02639
BDU:2015-02640
BDU:2015-05014
BDU:2015-05015
BDU:2015-05016
BDU:2015-05017
CVE-2008-3272
DSA-1630-1
DSA-1636-1
RHSA-2008:0857
RHSA-2008:0885
RHSA-2008:0972
RHSA-2008_0885
RHSA-2008_0972

Produtos afetados

Linux Kernel
Red Hat