Willy Tarreau 82e68f7ffe sound: ensure device number is valid in snd_seq_oss_synth_make_info
snd_seq_oss_synth_make_info() incorrectly reports information
to userspace without first checking for the validity of the
device number, leading to possible information leak (CVE-2008-3272).

Reported-By: Tobias Klein <tk@trapkit.de>
Acked-and-tested-by: Takashi Iwai <tiwai@suse.de>
Cc: stable@kernel.org
Signed-off-by: Willy Tarreau <w@1wt.eu>
Signed-off-by: Linus Torvalds <torvalds@linux-foundation.org>
2008-08-04 17:03:26 -07:00
..
2008-05-27 15:56:20 +02:00
2008-05-27 15:56:20 +02:00
2008-05-27 15:56:20 +02:00
2008-07-10 09:32:58 +02:00
2008-07-29 08:09:44 +09:00
2008-05-27 15:56:20 +02:00
2007-02-09 09:03:54 +01:00
2008-05-27 15:56:20 +02:00
2008-01-31 17:29:48 +01:00
2007-05-21 09:18:19 -07:00