Release date:
Updated on:
Affected Systems:
Linux kernel 2.6.0-2.6.37
Description:
--------------------------------------------------------------------------------
Bugtraq id: 45629
Linux Kernel is the Kernel used by open source Linux.
Linux Kernel has multiple Implementation Vulnerabilities. Local attackers can exploit this vulnerability to leak some system information and gain Elevation of Privilege.
These vulnerabilities are caused:
1) The "load_mixer_volumes ()" function in sound/oss/soundcard. c has a boundary error, which can cause a buffer overflow. It may be possible to execute arbitrary code in Kernel mode by sending a specially crafted SOUND_MIXER_SETLEVELS Io;
2) An error exists in the "load_mixer_volumes ()" function of sound/oss/soundcard. c, which may cause leakage of some Kernel memory by sending specially crafted SOUND_MIXER_SETLEVELS IOCTL.
<* Source: Dan Rosenberg
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.kernel.org/