4.9
CVSSv2

CVE-2013-6834

Published: 21/11/2013 Updated: 04/03/2014
CVSS v2 Base Score: 4.9 | Impact Score: 6.9 | Exploitability Score: 3.9
VMScore: 436
Vector: AV:L/AC:L/Au:N/C:C/I:N/A:N

Vulnerability Summary

The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and previous versions does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

Vulnerable Product Search on Vulmon Subscribe to Product

freebsd freebsd 8.2

freebsd freebsd 8.0

freebsd freebsd 6.3

freebsd freebsd 6.1

freebsd freebsd 5.2.1

freebsd freebsd 5.1

freebsd freebsd 4.5

freebsd freebsd 4.3

freebsd freebsd 3.5.1

freebsd freebsd 3.4

freebsd freebsd 2.2.8

freebsd freebsd 2.2.6

freebsd freebsd 2.1.7.1

freebsd freebsd 2.1.6.1

freebsd freebsd 2.0

freebsd freebsd 1.5

freebsd freebsd 1.0

freebsd freebsd 9.2

freebsd freebsd 7.4

freebsd freebsd 7.3

freebsd freebsd 7.2

freebsd freebsd 7.1

freebsd freebsd 7.0

freebsd freebsd 4.9

freebsd freebsd 4.8

freebsd freebsd 4.7

freebsd freebsd 4.6.2

freebsd freebsd 3.3

freebsd freebsd 3.2

freebsd freebsd 3.1

freebsd freebsd 3.0

freebsd freebsd 2.1.6

freebsd freebsd 2.1.5

freebsd freebsd 2.1.0

freebsd freebsd 2.1

freebsd freebsd 2.0.5

freebsd freebsd 9.1

freebsd freebsd 9.0

freebsd freebsd 8.4

freebsd freebsd 6.0

freebsd freebsd 5.5

freebsd freebsd 5.4

freebsd freebsd 5.3

freebsd freebsd 4.2

freebsd freebsd 4.11

freebsd freebsd 4.10

freebsd freebsd 4.1.1

freebsd freebsd 4.1

freebsd freebsd 2.2.4

freebsd freebsd 2.2.3

freebsd freebsd 2.2.2

freebsd freebsd 2.2.1

freebsd freebsd 1.2

freebsd freebsd 1.1.5.1

freebsd freebsd 1.1.5

freebsd freebsd 1.1

freebsd freebsd 8.3

freebsd freebsd 8.1

freebsd freebsd 6.4

freebsd freebsd 6.2

freebsd freebsd 5.2

freebsd freebsd 5.0

freebsd freebsd 4.6

freebsd freebsd 4.4

freebsd freebsd 4.0

freebsd freebsd 3.5

freebsd freebsd 2.2.7

freebsd freebsd 2.2.5

freebsd freebsd 2.2

freebsd freebsd 2.1.7

freebsd freebsd 2.0.1

freebsd freebsd

freebsd freebsd 0.4_1

Vendor Advisories

Debian Bug report logs - #730518 kfreebsd-10: CVE-2013-6832 nand memory leak in ioctl Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 26 Nov 2013 02:39:02 UTC Severity: grave Tags: fixed-upstrea ...
Debian Bug report logs - #730519 kfreebsd-10: CVE-2013-6834, CVE-2013-6833: qlxgbe/qlxge memory leaks in ioctl Package: kfreebsd-10; Maintainer for kfreebsd-10 is GNU/kFreeBSD Maintainers <debian-bsd@listsdebianorg>; Reported by: Steven Chamberlain <steven@pyroeuorg> Date: Tue, 26 Nov 2013 03:00:01 UTC Severity: ...