CVE-2013-6832: Infoleak
The nandioctl function in sys/dev/nand/nandgeom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6832?
CVE-2013-6832 has been classified as a medium severity vulnerability due to its potential to leak sensitive kernel memory information.
How do I fix CVE-2013-6832?
To fix CVE-2013-6832, update to a patched version of FreeBSD that addresses this vulnerability.
Who is affected by CVE-2013-6832?
CVE-2013-6832 affects local users on FreeBSD versions 10 and earlier.
What is the impact of CVE-2013-6832?
The impact of CVE-2013-6832 is that local users may gain unauthorized access to sensitive information in kernel memory.
What systems are vulnerable to CVE-2013-6832?
FreeBSD systems prior to version 10.0 are vulnerable to CVE-2013-6832.