Integer Signedness Error in FireWire Drivers Affects Multiple BSD Vendors
CVE-2006-6013
Currently unrated
Key Information:
- Vendor
Midnightbsd
- Vendor
- CVE Published:
- 21 November 2006
What is CVE-2006-6013?
This vulnerability is due to an integer signedness error within the fw_ioctl function in FireWire drivers for various BSD operating systems. Local users can exploit this error by passing negative values to the crom_buf->len parameter in an FW_GCROM command, potentially allowing them to read arbitrary memory contents from the kernel's memory space. This poses a significant security risk as it can lead to unauthorized access to sensitive information.
