LOW · 2.1

CVE-2006-6013

Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CUR...

Vulnerability Description

Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
DragonflybsdDragonflybsdAll versions
FreebsdFreebsd5.5
MidnightbsdMidnightbsd0.1-current
NetbsdNetbsd2.0.4
TrustedbsdTrustedbsdAll versions

References

FAQ

What is CVE-2006-6013?

CVE-2006-6013 is a vulnerability with a CVSS score of 2.1 (LOW). Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CUR...

How severe is CVE-2006-6013?

CVE-2006-6013 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-6013?

Check the references section above for vendor advisories and patch information. Affected products include: Dragonflybsd Dragonflybsd, Freebsd Freebsd, Midnightbsd Midnightbsd, Netbsd Netbsd, Trustedbsd Trustedbsd.