CVE-2013-6833: Input Validation
The qlseioctl function in sys/dev/qlxge/qlsioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-6833?
CVE-2013-6833 is considered a medium severity vulnerability due to its potential to expose sensitive information from kernel memory.
How can I fix CVE-2013-6833?
To fix CVE-2013-6833, apply the latest security patches provided by FreeBSD that address this ioctl parameter validation issue.
Who is affected by CVE-2013-6833?
CVE-2013-6833 affects FreeBSD 10 and earlier versions, allowing local users to exploit it.
What type of attack does CVE-2013-6833 enable?
CVE-2013-6833 enables a local privilege escalation attack that can lead to the disclosure of sensitive kernel memory.
Is there a workaround for CVE-2013-6833?
Currently, the best practice is to update to a supported version of FreeBSD that has patched CVE-2013-6833.