PT-2010-5694 · Linux+2 · Linux Kernel+2

Dan Rosenberg

·

Publicado

1970-01-01

·

Atualizado

2020-08-13

·

CVE-2010-4081

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions SUSE Linux Enterprise (affected versions not specified) Linux kernel versions prior to 2.6.36-rc6
Description The issue concerns multiple vulnerabilities in the Linux kernel, specifically affecting the snd hdspm hwdep ioctl function in sound/pci/rme9652/hdspm.c. These vulnerabilities can be exploited remotely and may lead to unauthorized access to sensitive information. Local users can obtain potentially sensitive information from kernel stack memory via an SNDRV HDSPM IOCTL GET CONFIG INFO ioctl call.
Recommendations For Linux kernel versions prior to 2.6.36-rc6, update to version 2.6.36-rc6 or later to resolve the issue. At the moment, there is no information about a newer version of SUSE Linux Enterprise that contains a fix for this vulnerability.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2015-04589
BDU:2015-04590
CVE-2010-4081
DSA-2126-1
RHSA-2011:0007
RHSA-2011:0017
RHSA-2011_0007
RHSA-2011_0017

Produtos afetados

Linux Kernel
Red Hat
Suse Linux Enterprise