Bug 288961 (CVE-2007-4571)

Summary: CVE-2007-4571 ALSA memory disclosure flaw
Product: [Other] Security Response Reporter: Mark J. Cox <mjc>
Component: vulnerabilityAssignee: Red Hat Product Security <security-response-team>
Status: CLOSED ERRATA QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anton, dhoward, jbaron, kernel-mgr, kreilly, kseifried, peterm
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: Bug Fix
Doc Text:
Story Points: ---
Clone Of: Environment:
Last Closed: 2011-09-28 22:58:56 UTC Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 297741, 297751, 297761, 297771    
Bug Blocks:    
Attachments:
Description Flags
Proposed patch none

Description Mark J. Cox 2007-09-13 08:32:05 UTC
iDefense reported a flaw in ALSA snd_mem_proc_read.  A local user who has the
ability to read the /proc/driver/snd-page-alloc file could potentially gain
access to read sensitive information from kernel memory.

CVSS v2 Base score: 2.1  (Low) (AV:L/AC:L/Au:N/C:P/I:N/A:N)

Acknowledgements:

Red Hat would like to credit iDefense and Neil Kettle for reporting this issue.

Comment 2 Mark J. Cox 2007-09-13 08:33:29 UTC
Created attachment 194421 [details]
Proposed patch

Comment 3 Mark J. Cox 2007-09-13 08:40:15 UTC
        Doesn't Affect: rhel-2.1 (no snd_mem_proc_read)
        Doesn't Affect: rhel-3 (no snd_mem_proc_read)
        Probably Affects: rhel-4
        Probably Affects: rhel-5


Comment 5 Mark J. Cox 2007-09-14 09:06:25 UTC
Exploiting this issue will give the user the ability to see a number of
uninitialized bytes, up to 41 bytes, but they have no control over what they see.

Comment 11 Mark J. Cox 2007-09-25 15:53:07 UTC
Now public via
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=600
removing embargo

Comment 17 Kurt Seifried 2011-09-28 22:58:56 UTC
All children bugs have been closed, parent is no longer needed.