CVE-2006-6013
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/11/2006
Last modified:
17/10/2018
Description
Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.
Impact
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:dragonflybsd:dragonflybsd:*:*:*:*:*:*:*:* | ||
cpe:2.3:o:freebsd:freebsd:5.5:*:*:*:*:*:*:* | ||
cpe:2.3:o:midnightbsd:midnightbsd:0.1-current:*:*:*:*:*:*:* | ||
cpe:2.3:o:netbsd:netbsd:2.0.4:*:*:*:*:*:*:* | ||
cpe:2.3:o:trustedbsd:trustedbsd:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/fulldisclosure/2006-11/0261.html
- http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/dev/ieee1394/fwdev.c
- http://mail-index.netbsd.org/tech-security/2006/11/16/0001.html
- http://mail-index.netbsd.org/tech-security/2006/12/14/0002.html
- http://secunia.com/advisories/22917
- http://security.freebsd.org/advisories/FreeBSD-SA-06:25.kmem.asc
- http://securitytracker.com/id?1017344=
- http://www.dragonflybsd.org/cvsweb/src/sys/bus/firewire/fwdev.c
- http://www.kernelhacking.com/bsdadv1.txt
- http://www.securityfocus.com/archive/1/451629/100/0/threaded
- http://www.securityfocus.com/archive/1/451637/100/0/threaded
- http://www.securityfocus.com/archive/1/451677/100/0/threaded
- http://www.securityfocus.com/archive/1/451698/100/0/threaded
- http://www.securityfocus.com/archive/1/451861/100/0/threaded
- http://www.securityfocus.com/archive/1/452124/100/0/threaded
- http://www.securityfocus.com/archive/1/452264/100/0/threaded
- http://www.securityfocus.com/archive/1/452331/100/0/threaded
- http://www.securityfocus.com/bid/21089
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30347