4.9
CVSSv2

CVE-2013-6832

Published: 21/11/2013 Updated: 25/11/2013
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and previous versions does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 8.3

freebsd freebsd 8.2

freebsd freebsd 6.4

freebsd freebsd 6.3

freebsd freebsd 5.2.1

freebsd freebsd 5.2

freebsd freebsd 4.6

freebsd freebsd 4.5

freebsd freebsd 4.0

freebsd freebsd 3.5.1

freebsd freebsd 2.2.8

freebsd freebsd 2.2.7

freebsd freebsd 2.2

freebsd freebsd 2.1.7.1

freebsd freebsd 2.0.1

freebsd freebsd 2.0

freebsd freebsd 1.0

freebsd freebsd 0.4_1

freebsd freebsd 9.0

freebsd freebsd 8.4

freebsd freebsd 7.2

freebsd freebsd 7.1

freebsd freebsd 7.0

freebsd freebsd 5.4

freebsd freebsd 5.3

freebsd freebsd 4.7

freebsd freebsd 4.6.2

freebsd freebsd 4.1.1

freebsd freebsd 4.1

freebsd freebsd 3.1

freebsd freebsd 3.0

freebsd freebsd 2.2.2

freebsd freebsd 2.2.1

freebsd freebsd 2.1

freebsd freebsd 2.0.5

freebsd freebsd 1.1.5

freebsd freebsd 1.1

freebsd freebsd 9.1

freebsd freebsd 7.4

freebsd freebsd 7.3

freebsd freebsd 6.0

freebsd freebsd 5.5

freebsd freebsd 4.9

freebsd freebsd 4.8

freebsd freebsd 4.2

freebsd freebsd 4.11

freebsd freebsd 4.10

freebsd freebsd 3.3

freebsd freebsd 3.2

freebsd freebsd 2.2.4

freebsd freebsd 2.2.3

freebsd freebsd 2.1.5

freebsd freebsd 2.1.0

freebsd freebsd 1.2

freebsd freebsd 1.1.5.1

freebsd freebsd 8.1

freebsd freebsd 8.0

freebsd freebsd 6.2

freebsd freebsd 6.1

freebsd freebsd 5.1

freebsd freebsd 5.0

freebsd freebsd 4.4

freebsd freebsd 4.3

freebsd freebsd 3.5

freebsd freebsd 3.4

freebsd freebsd 2.2.6

freebsd freebsd 2.2.5

freebsd freebsd 2.1.7

freebsd freebsd 2.1.6.1

freebsd freebsd 2.1.6

freebsd freebsd

freebsd freebsd 1.5

freebsd freebsd 9.2

Vendor Advisories

Debian Bug report logs - #730518 kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 26 Nov 2013 02:39:02 UTC Severity: grave Tags: fixed-upstrea ...
Debian Bug report logs - #730519 kfreebsd-10: CVE-2013-6834, CVE-2013-6833: qlxgbe/qlxge memory leaks in ioctl Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 26 Nov 2013 03:00:01 UTC Severity: ...