The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.
References
Link Providers
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ccec6e2c4a74adf76ed4e2478091a311b1806212 cve-icon cve-icon
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.8 cve-icon cve-icon
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=600 cve-icon cve-icon
http://secunia.com/advisories/26918 cve-icon cve-icon
http://secunia.com/advisories/26980 cve-icon cve-icon
http://secunia.com/advisories/26989 cve-icon cve-icon
http://secunia.com/advisories/27101 cve-icon cve-icon
http://secunia.com/advisories/27227 cve-icon cve-icon
http://secunia.com/advisories/27436 cve-icon cve-icon
http://secunia.com/advisories/27747 cve-icon cve-icon
http://secunia.com/advisories/27824 cve-icon cve-icon
http://secunia.com/advisories/28626 cve-icon cve-icon
http://secunia.com/advisories/29054 cve-icon cve-icon
http://secunia.com/advisories/30769 cve-icon cve-icon
http://support.avaya.com/elmodocs2/security/ASA-2007-474.htm cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1479 cve-icon cve-icon
http://www.debian.org/security/2008/dsa-1505 cve-icon cve-icon
http://www.novell.com/linux/security/advisories/2007_53_kernel.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0939.html cve-icon cve-icon
http://www.redhat.com/support/errata/RHSA-2007-0993.html cve-icon cve-icon
http://www.securityfocus.com/bid/25807 cve-icon cve-icon
http://www.securitytracker.com/id?1018734 cve-icon cve-icon
http://www.ubuntu.com/usn/usn-618-1 cve-icon cve-icon
http://www.vupen.com/english/advisories/2007/3272 cve-icon cve-icon
https://exchange.xforce.ibmcloud.com/vulnerabilities/36780 cve-icon cve-icon
https://issues.rpath.com/browse/RPL-1761 cve-icon cve-icon
https://nvd.nist.gov/vuln/detail/CVE-2007-4571 cve-icon
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9053 cve-icon cve-icon
https://www.cve.org/CVERecord?id=CVE-2007-4571 cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00083.html cve-icon cve-icon
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00436.html cve-icon cve-icon
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published: 2007-09-26T10:00:00

Updated: 2024-08-07T15:01:09.870Z

Reserved: 2007-08-28T00:00:00

Link: CVE-2007-4571

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-09-26T10:17:00.000

Modified: 2023-02-13T02:18:20.370

Link: CVE-2007-4571

cve-icon Redhat

Severity : Moderate

Publid Date: 2007-09-25T00:00:00Z

Links: CVE-2007-4571 - Bugzilla