CVE Database
/

CVE-2006-6013

Back to search

CVE-2006-6013

Published: Nov 21, 2006

Modified: Aug 7, 2024

PUBLISHED

Description

Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.

VendorProductVersions

n/a

n/a

affected
n/a

References

1017344
vdb-entry
x_refsource_SECTRACK
FreeBSD-SA-06:25
vendor-advisory
x_refsource_FREEBSD
21089
vdb-entry
x_refsource_BID
22917
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now