CVE-2006-6013: Integer Overflow
Integer signedness error in the fwioctl (FWIOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crombuf->len in an FWGCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6013?
CVE-2006-6013 is considered to have a moderate severity due to potential denial of service vulnerabilities.
How do I fix CVE-2006-6013?
To fix CVE-2006-6013, users should upgrade to the latest versions of affected BSD operating systems that contain the relevant patches.
Which BSD versions are affected by CVE-2006-6013?
CVE-2006-6013 affects various BSD kernels including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT, and NetBSD versions prior to specified patches.
What type of vulnerability is CVE-2006-6013?
CVE-2006-6013 is classified as an integer signedness error within the FireWire drivers.
Can CVE-2006-6013 be exploited remotely?
Yes, CVE-2006-6013 can potentially be exploited remotely if specific conditions are met, making certain systems vulnerable to denial of service.