CVE-2008-3272
08.08.2008, 18:41
The snd_seq_oss_synth_make_info function in sound/core/seq/oss/seq_oss_synth.c in the sound subsystem in the Linux kernel before 2.6.27-rc2 does not verify that the device number is within the range defined by max_synthdev before returning certain data to the caller, which allows local users to obtain sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
linux | linux_kernel | 𝑥 < 2.6.27 |
linux | linux_kernel | 2.6.27 |
linux | linux_kernel | 2.6.27:rc1 |
debian | debian_linux | 4.0 |
canonical | ubuntu_linux | 6.06 |
canonical | ubuntu_linux | 7.04 |
canonical | ubuntu_linux | 7.10 |
canonical | ubuntu_linux | 8.04 |
redhat | enterprise_linux_desktop | 4.0 |
redhat | enterprise_linux_eus | 4.7 |
redhat | enterprise_linux_server | 4.0 |
redhat | enterprise_linux_workstation | 4.0 |
𝑥
= Vulnerable software versions

Ubuntu Releases
Ubuntu Product | |||||||||
---|---|---|---|---|---|---|---|---|---|
linux |
| ||||||||
linux-source-2.6.15 |
| ||||||||
linux-source-2.6.20 |
| ||||||||
linux-source-2.6.22 |
|
Common Weakness Enumeration
References