CVE-2008-3272

The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
2.1 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 20%
VendorProductVersion
linuxlinux_kernel
𝑥
< 2.6.27
linuxlinux_kernel
2.6.27
linuxlinux_kernel
2.6.27:rc1
debiandebian_linux
4.0
canonicalubuntu_linux
6.06
canonicalubuntu_linux
7.04
canonicalubuntu_linux
7.10
canonicalubuntu_linux
8.04
redhatenterprise_linux_desktop
4.0
redhatenterprise_linux_eus
4.7
redhatenterprise_linux_server
4.0
redhatenterprise_linux_workstation
4.0
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
hardy
Fixed 2.6.24-19.41
released
gutsy
dne
feisty
dne
dapper
dne
linux-source-2.6.15
hardy
dne
gutsy
dne
feisty
dne
dapper
Fixed 2.6.15-52.71
released
linux-source-2.6.20
hardy
dne
gutsy
dne
feisty
Fixed 2.6.20-17.39
released
dapper
dne
linux-source-2.6.22
hardy
dne
gutsy
Fixed 2.6.22-15.58
released
feisty
dne
dapper
dne
References