PT-2008-6906 · Linux+1 · Linux Kernel+1

Tobias Klein

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2008-3272

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions linux-headers-2.6.24-etchnhalf.1-all-mips versions linux-headers-2.6.24-etchnhalf.1-r4k-ip22 versions linux-headers-2.6.24-etchnhalf.1-r5k-ip32 versions linux-image-2.6.24-etchnhalf.1-r4k-ip22 versions linux-image-2.6.24-etchnhalf.1-r5k-ip32 versions kernel-rt debug-debuginfo versions kernel-rt debug-debugsource versions kernel-rt-debuginfo versions kernel-rt-debugsource versions Linux kernel versions prior to 2.6.27-rc2
Description The issue involves multiple vulnerabilities in various Linux kernel and operating system packages, which can lead to a breach of confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. The snd seq oss synth make info function in the sound subsystem of the Linux kernel does not verify that the device number is within the defined range before returning certain data to the caller, allowing local users to obtain sensitive information.
Recommendations For linux-headers-2.6.24-etchnhalf.1-all-mips, update to a version that includes the necessary security patches. For linux-headers-2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches. For linux-headers-2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches. For linux-image-2.6.24-etchnhalf.1-r4k-ip22, update to a version that includes the necessary security patches. For linux-image-2.6.24-etchnhalf.1-r5k-ip32, update to a version that includes the necessary security patches. For kernel-rt debug-debuginfo, update to a version that includes the necessary security patches. For kernel-rt debug-debugsource, update to a version that includes the necessary security patches. For kernel-rt-debuginfo, update to a version that includes the necessary security patches. For kernel-rt-debugsource, update to a version that includes the necessary security patches. For Linux kernel versions prior to 2.6.27-rc2, update to version 2.6.27-rc2 or later to address the vulnerability in the snd seq oss synth make info function.

Fix

Buffer Overflow

Information Disclosure

Weakness Enumeration

Related Identifiers

BDU:2015-02636
BDU:2015-02637
BDU:2015-02638
BDU:2015-02639
BDU:2015-02640
BDU:2015-05014
BDU:2015-05015
BDU:2015-05016
BDU:2015-05017
CVE-2008-3272
DSA-1630-1
DSA-1636-1
RHSA-2008:0857
RHSA-2008:0885
RHSA-2008:0972
RHSA-2008_0885
RHSA-2008_0972

Affected Products

Linux Kernel
Red Hat