Description
The snd_mem_proc_read function in sound/core/memalloc.c in the Advanced Linux Sound Architecture (ALSA) in the Linux kernel before 2.6.22.8 does not return the correct write size, which allows local users to obtain sensitive information (kernel memory contents) via a small count argument, as demonstrated by multiple reads of /proc/driver/snd-page-alloc.
Exploits
306052007-09-21localLinux
Linux Kernel 2.6.x - ALSA snd-page-alloc Local Proc File Information Disclosure
By Karimo_DM
References
secalert@redhat.com
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ccec6e2c4a74adf76ed4e2478091a311b1806212secalert@redhat.com
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.8secalert@redhat.com
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=600secalert@redhat.com
http://secunia.com/advisories/26918secalert@redhat.com
http://secunia.com/advisories/26980secalert@redhat.com
http://secunia.com/advisories/26989secalert@redhat.com
http://secunia.com/advisories/27101secalert@redhat.com
http://secunia.com/advisories/27227secalert@redhat.com
http://secunia.com/advisories/27436secalert@redhat.com
http://secunia.com/advisories/27747secalert@redhat.com
http://secunia.com/advisories/27824secalert@redhat.com
http://secunia.com/advisories/28626secalert@redhat.com
http://secunia.com/advisories/29054secalert@redhat.com
http://secunia.com/advisories/30769secalert@redhat.com
http://support.avaya.com/elmodocs2/security/ASA-2007-474.htmsecalert@redhat.com
http://www.debian.org/security/2008/dsa-1479secalert@redhat.com
http://www.debian.org/security/2008/dsa-1505secalert@redhat.com
http://www.novell.com/linux/security/advisories/2007_53_kernel.htmlsecalert@redhat.com
http://www.redhat.com/support/errata/RHSA-2007-0939.htmlsecalert@redhat.com
http://www.redhat.com/support/errata/RHSA-2007-0993.htmlsecalert@redhat.com
http://www.securityfocus.com/bid/25807secalert@redhat.com
http://www.securitytracker.com/id?1018734secalert@redhat.com
http://www.ubuntu.com/usn/usn-618-1secalert@redhat.com
http://www.vupen.com/english/advisories/2007/3272secalert@redhat.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/36780secalert@redhat.com
https://issues.rpath.com/browse/RPL-1761secalert@redhat.com
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9053secalert@redhat.com
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00083.htmlsecalert@redhat.com
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00436.htmlaf854a3a-2127-422b-91ae-364da2661108
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ccec6e2c4a74adf76ed4e2478091a311b1806212af854a3a-2127-422b-91ae-364da2661108
http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.22.8af854a3a-2127-422b-91ae-364da2661108
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=600af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26918af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26980af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/26989af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27101af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27227af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27436af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27747af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/27824af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/28626af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/29054af854a3a-2127-422b-91ae-364da2661108
http://secunia.com/advisories/30769af854a3a-2127-422b-91ae-364da2661108
http://support.avaya.com/elmodocs2/security/ASA-2007-474.htmaf854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1479af854a3a-2127-422b-91ae-364da2661108
http://www.debian.org/security/2008/dsa-1505af854a3a-2127-422b-91ae-364da2661108
http://www.novell.com/linux/security/advisories/2007_53_kernel.htmlaf854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0939.htmlaf854a3a-2127-422b-91ae-364da2661108
http://www.redhat.com/support/errata/RHSA-2007-0993.htmlaf854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/25807af854a3a-2127-422b-91ae-364da2661108
http://www.securitytracker.com/id?1018734af854a3a-2127-422b-91ae-364da2661108
http://www.ubuntu.com/usn/usn-618-1af854a3a-2127-422b-91ae-364da2661108
http://www.vupen.com/english/advisories/2007/3272af854a3a-2127-422b-91ae-364da2661108
https://exchange.xforce.ibmcloud.com/vulnerabilities/36780af854a3a-2127-422b-91ae-364da2661108
https://issues.rpath.com/browse/RPL-1761af854a3a-2127-422b-91ae-364da2661108
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9053af854a3a-2127-422b-91ae-364da2661108
https://www.redhat.com/archives/fedora-package-announce/2007-October/msg00083.htmlaf854a3a-2127-422b-91ae-364da2661108
https://www.redhat.com/archives/fedora-package-announce/2007-September/msg00436.html