Back to search
CVE-2007-4571
Published: Sep 26, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
27747
third-party-advisory
x_refsource_SECUNIA
27227
third-party-advisory
x_refsource_SECUNIA
SUSE-SA:2007:053
vendor-advisory
x_refsource_SUSE
1018734
vdb-entry
x_refsource_SECTRACK
USN-618-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2007:0939
vendor-advisory
x_refsource_REDHAT
ADV-2007-3272
vdb-entry
x_refsource_VUPEN
28626
third-party-advisory
x_refsource_SECUNIA
29054
third-party-advisory
x_refsource_SECUNIA
oval:org.mitre.oval:def:9053
vdb-entry
signature
x_refsource_OVAL
DSA-1479
vendor-advisory
x_refsource_DEBIAN
FEDORA-2007-2349
vendor-advisory
x_refsource_FEDORA
27824
third-party-advisory
x_refsource_SECUNIA
25807
vdb-entry
x_refsource_BID
26989
third-party-advisory
x_refsource_SECUNIA
http://support.avaya.com/elmodocs2/security/ASA-2007-474.htm
x_refsource_CONFIRM
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.8
x_refsource_CONFIRM
RHSA-2007:0993
vendor-advisory
x_refsource_REDHAT
https://issues.rpath.com/browse/RPL-1761
x_refsource_CONFIRM
26980
third-party-advisory
x_refsource_SECUNIA
DSA-1505
vendor-advisory
x_refsource_DEBIAN
linux-sndpagealloc-information-disclosure(36780)
vdb-entry
x_refsource_XF
20070925 Linux Kernel ALSA snd_mem_proc_read Information Disclosure Vulnerability
third-party-advisory
x_refsource_IDEFENSE
30769
third-party-advisory
x_refsource_SECUNIA
27101
third-party-advisory
x_refsource_SECUNIA
FEDORA-2007-714
vendor-advisory
x_refsource_FEDORA
27436
third-party-advisory
x_refsource_SECUNIA
26918
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now