Back to search
CVE-2010-4527
Published: Jan 13, 2011
Modified: Aug 7, 2024
PUBLISHED
Description
The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
[oss-security] 20101231 Re: CVE request: kernel: buffer overflow in OSS load_mixer_volumes
mailing-list
x_refsource_MLIST
https://bugzilla.redhat.com/show_bug.cgi?id=667615
x_refsource_CONFIRM
http://www.kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.37
x_refsource_CONFIRM
45629
vdb-entry
x_refsource_BID
[oss-security] 20101230 CVE request: kernel: buffer overflow in OSS load_mixer_volumes
mailing-list
x_refsource_MLIST
42765
third-party-advisory
x_refsource_SECUNIA
ADV-2011-0375
vdb-entry
x_refsource_VUPEN
SUSE-SA:2011:008
vendor-advisory
x_refsource_SUSE
43291
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now