PT-2008-6906 · Linux+1 · Linux Kernel+1
Tobias Klein
·
Published
1970-01-01
·
Updated
2023-02-13
·
CVE-2008-3272
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
linux-headers-2.6.24-etchnhalf.1-all-mips versions
linux-headers-2.6.24-etchnhalf.1-r4k-ip22 versions
linux-headers-2.6.24-etchnhalf.1-r5k-ip32 versions
linux-image-2.6.24-etchnhalf.1-r4k-ip22 versions
linux-image-2.6.24-etchnhalf.1-r5k-ip32 versions
kernel-rt debug-debuginfo versions
kernel-rt debug-debugsource versions
kernel-rt-debuginfo versions
kernel-rt-debugsource versions
Linux kernel versions prior to 2.6.27-rc2
Description
The issue involves multiple vulnerabilities in various Linux kernel and operating system packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The
snd seq oss synth make info function in the sound subsystem of the Linux kernel does not verify that the device number is within the defined range before returning certain data to the caller, allowing local users to obtain sensitive information.Recommendations
For linux-headers-2.6.24-etchnhalf.1-all-mips, update to a version that includes the necessary security patches.
For linux-headers-2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches.
For linux-headers-2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches.
For linux-image-2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches.
For linux-image-2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches.
For kernel-rt debug-debuginfo, update to a version that includes the necessary security patches.
For kernel-rt debug-debugsource, update to a version that includes the necessary security patches.
For kernel-rt-debuginfo, update to a version that includes the necessary security patches.
For kernel-rt-debugsource, update to a version that includes the necessary security patches.
For Linux kernel versions prior to 2.6.27-rc2, update to version 2.6.27-rc2 or later to address the vulnerability in the
snd seq oss synth make info function.Fix
Buffer Overflow
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Linux Kernel
Red Hat