CVE-2008-3272
published 2008-08-08CVE-2008-3272: The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.42%
34.2th percentile
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| linux | linux_kernel | < 2.6.27 | 2.6.27 |
| linux | linux_kernel | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_ubuntu4.9MEDIUM
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2008-08-25·CVSS 4.9
CVE-2008-3272 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Linux kernel vulnerabilities
It was discovered that there were multiple NULL-pointer function
dereferences in the Linux kernel terminal handling code. A local attacker
could exploit this to execute arbitrary code as root, or crash the system,
leading to a denial of service. (CVE-2008-2812)
The do_change_type routine did not correctly validation administrative
users. A local attacker could exploit this to block mount points or cause
private mounts to be shared, leading to denial of service or a possible
loss of privacy. (CVE-2008-2931)
Tobias Klein discovered that the OSS interface through ALSA did not
correctly validate the device number. A local attacker could exploit this
to access sensitive kernel memory, leading to a denial of service or
Red Hat
kernel snd_seq_oss_synth_make_info leak
vendor_redhat·2008-08-02·CVSS 2.1
CVE-2008-3272 [LOW] kernel snd_seq_oss_synth_make_info leak
kernel snd_seq_oss_synth_make_info leak
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
GHSA
GHSA-qg44-g4p3-cf6x: The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth
ghsa_unreviewed·2022-05-01
CVE-2008-3272 [LOW] CWE-200 GHSA-qg44-g4p3-cf6x: The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=82e68f7ffec3800425f2391c8c86277606860442http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0972.htmlhttp://secunia.com/advisories/31366http://secunia.com/advisories/31551http://secunia.com/advisories/31614http://secunia.com/advisories/31836http://secunia.com/advisories/31881http://secunia.com/advisories/32023http://secunia.com/advisories/32103http://secunia.com/advisories/32104http://secunia.com/advisories/32190http://secunia.com/advisories/32370http://secunia.com/advisories/32759http://secunia.com/advisories/32799http://www.debian.org/security/2008/dsa-1630http://www.debian.org/security/2008/dsa-1636http://www.mandriva.com/security/advisories?name=MDVSA-2008:220http://www.redhat.com/support/errata/RHSA-2008-0857.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0885.htmlhttp://www.securityfocus.com/bid/30559http://www.securitytracker.com/id?1020636http://www.vupen.com/english/advisories/2008/2307https://exchange.xforce.ibmcloud.com/vulnerabilities/44225https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11182https://usn.ubuntu.com/637-1/http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=82e68f7ffec3800425f2391c8c86277606860442http://kernel.org/pub/linux/kernel/v2.6/testing/ChangeLog-2.6.27-rc2http://lists.opensuse.org/opensuse-security-announce/2008-10/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00001.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-10/msg00008.htmlhttp://lists.opensuse.org/opensuse-security-announce/2008-11/msg00001.htmlhttp://rhn.redhat.com/errata/RHSA-2008-0972.htmlhttp://secunia.com/advisories/31366http://secunia.com/advisories/31551http://secunia.com/advisories/31614http://secunia.com/advisories/31836http://secunia.com/advisories/31881http://secunia.com/advisories/32023http://secunia.com/advisories/32103http://secunia.com/advisories/32104http://secunia.com/advisories/32190http://secunia.com/advisories/32370http://secunia.com/advisories/32759http://secunia.com/advisories/32799http://www.debian.org/security/2008/dsa-1630http://www.debian.org/security/2008/dsa-1636http://www.mandriva.com/security/advisories?name=MDVSA-2008:220http://www.redhat.com/support/errata/RHSA-2008-0857.htmlhttp://www.redhat.com/support/errata/RHSA-2008-0885.htmlhttp://www.securityfocus.com/bid/30559http://www.securitytracker.com/id?1020636http://www.vupen.com/english/advisories/2008/2307https://exchange.xforce.ibmcloud.com/vulnerabilities/44225https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A11182https://usn.ubuntu.com/637-1/
2008-08-08
Published