CVE-2008-3272

EUVD-2008-3260
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
Affected Products (NVD)
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.27
linuxlinux_kernel
2.6.27
linuxlinux_kernel
2.6.27:rc1
debiandebian_linux
4.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
redhatenterprise_linux_desktop
4.0
redhatenterprise_linux_eus
4.7
redhatenterprise_linux_server
4.0
redhatenterprise_linux_workstation
4.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
dapper
dne
feisty
dne
gutsy
dne
hardy
Fixed 2.6.24-19.41
released
linux-source-2.6.15
dapper
Fixed 2.6.15-52.71
released
feisty
dne
gutsy
dne
hardy
dne
linux-source-2.6.20
dapper
dne
feisty
Fixed 2.6.20-17.39
released
gutsy
dne
hardy
dne
linux-source-2.6.22
dapper
dne
feisty
dne
gutsy
Fixed 2.6.22-15.58
released
hardy
dne
References