Integer Signedness Error in FireWire Drivers Affects Multiple BSD Vendors
CVE-2006-6013

Currently unrated

Key Information:

Vendor
CVE Published:
21 November 2006

What is CVE-2006-6013?

This vulnerability is due to an integer signedness error within the fw_ioctl function in FireWire drivers for various BSD operating systems. Local users can exploit this error by passing negative values to the crom_buf->len parameter in an FW_GCROM command, potentially allowing them to read arbitrary memory contents from the kernel's memory space. This poses a significant security risk as it can lead to unauthorized access to sensitive information.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.