VEXID-125960
Published 2016-06-29 14:10:00
Last Modified 2017-09-01 01:29:00
AKA CVE-2012-6703
Summary Integer overflow in the snd_compr_allocate_buffer function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.6-rc6-next-20120917 allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.
CVSS Score 7.2
CVSS
Access Vector Local Adjacent Network
Access Complexity Low Medium High
Authentication None Single Multiple
Confidentiality None Partial Complete
Integrity None Partial Complete
Availability None Partial Complete
References
Type Content
Other 1031129
Vendor Advisory http://support.citrix.com/article/CTX200206