DescriptionEugene Teo (Security Response)
2008-08-06 01:59:34 UTC
Description of problem:
Tobias Klein reported that the snd_seq_oss_synth_make_info() function incorrectly reports information to userspace without first checking for the validity of the device number, leading to possible information leak.
Comment 1Eugene Teo (Security Response)
2008-08-06 02:03:22 UTC
This was addressed via:
MRG Realtime for RHEL 5 Server (RHSA-2008:0857)
Red Hat Enterprise Linux version 5 (RHSA-2008:0885)
Red Hat Enterprise Linux version 4 (RHSA-2008:0972)