>> Linux Kernel ALSA "snd_mem_proc_read()" Information Disclosure Issue
Title : Linux Kernel ALSA "snd_mem_proc_read()" Information Disclosure Issue VUPEN ID : VUPEN/ADV-2007-3272 CVE ID : CVE-2007-4571
Rated as : Low Risk
Remotely Exploitable : No Locally Exploitable : Yes Release Date : 2007-09-26
Technical Description
A vulnerability has been identified in Linux Kernel, which could be exploited by malicious users to disclose sensitive information. This issue is caused by an error in the "snd_mem_proc_read()" [sound/core/memalloc.c] function when handling multiple reads from the "/proc/driver/snd-page-alloc" file, which could be exploited by local attackers to cause portions of kernel memory to be leaked.