Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2010-4527

Опубликовано: 13 янв. 2011
Источник: ubuntu
Приоритет: medium
CVSS2: 6.9

Описание

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.6.39-0.0
hardy

released

2.6.24-29.89
karmic

ignored

lucid

released

2.6.32-29.57
maverick

released

2.6.35-27.47
natty

released

2.6.37-12.26
upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

ignored

end of life
lucid

released

2.6.32-313.25
maverick

ignored

end of life
natty

DNE

upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

ignored

end of life
lucid

released

2.6.31-609.26
maverick

DNE

natty

DNE

upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

DNE

lucid

released

2.6.35-28.50~lucid1
maverick

DNE

natty

DNE

upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
devel

DNE

hardy

DNE

lucid

not-affected

2.6.38-1.27~lucid1
maverick

DNE

natty

DNE

upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

DNE

hardy

DNE

karmic

ignored

end of life
lucid

released

2.6.32-214.30
maverick

released

2.6.32-414.30
natty

DNE

upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
dapper

released

2.6.15-57.96
devel

DNE

hardy

DNE

karmic

DNE

lucid

DNE

maverick

DNE

natty

DNE

upstream

released

2.6.37

Показывать по

РелизСтатусПримечание
dapper

DNE

devel

not-affected

2.6.38-1309.13
hardy

DNE

karmic

DNE

lucid

DNE

maverick

released

2.6.35-903.22
natty

not-affected

2.6.38-1201.2
upstream

released

2.6.37

Показывать по

6.9 Medium

CVSS2

Связанные уязвимости

redhat
почти 15 лет назад

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

nvd
почти 15 лет назад

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

debian
почти 15 лет назад

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS so ...

github
больше 3 лет назад

The load_mixer_volumes function in sound/oss/soundcard.c in the OSS sound subsystem in the Linux kernel before 2.6.37 incorrectly expects that a certain name field ends with a '\0' character, which allows local users to conduct buffer overflow attacks and gain privileges, or possibly obtain sensitive information from kernel memory, via a SOUND_MIXER_SETLEVELS ioctl call.

suse-cvrf
больше 13 лет назад

Security update for Kernel

6.9 Medium

CVSS2

Уязвимость CVE-2010-4527