FreeBSD VuXML: Documenting security issues in FreeBSD and the FreeBSD Ports Collection

CVE-2006-6013

This CVE name corresponds to:

Entered Topic
2007-02-27 FreeBSD -- Kernel memory disclosure in firewire(4)

The following information is adapted from the Common Vulnerabilities and Exposures (CVE) project. CVE and the CVE logo are trademarks of The MITRE Corporation. CVE content is Copyright 2005, The MITRE Corporation.

Details

Type Candidate
Name CVE-2006-6013
Phase Assigned(20061121)

Description

Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.

References

Source Reference
BUGTRAQ 20061115 DragonFlyBSD all versions FireWire IOCTL kernel integer overflow information disclousure
BUGTRAQ 20061115 FreeBSD all versions FireWire IOCTL kernel integer overflow information disclousure
BUGTRAQ 20061115 NetBSD all versions FireWire IOCTL kernel integer overflow information disclousure
BUGTRAQ 20061115 TrustedBSD* all versions FireWire IOCTL kernel integer overflow information disclousure
BUGTRAQ 20061116 Re: FreeBSD all versions FireWire IOCTL kernel integer overflow information disclousure
BUGTRAQ 20061120 RE: FreeBSD all versions FireWire IOCTL kernel integer overflow information disclousure
BUGTRAQ 20061121 Clarifying integer overflows vs. signedness errors
BUGTRAQ 20061122 Re: Clarifying integer overflows vs. signedness errors
FULLDISC 20061115 NetBSD all versions FireWire IOCTL kernel integer overflow information disclousure
MLIST [tech-security] 20061116 Re: [Full-disclosure] NetBSD all versions FireWire IOCTL kernel integer overflow information disclousure
MLIST [tech-security] 20061214 NetBSD Security Note 20061214-1: Kernel memory leakage in firewire interface
MISC http://www.dragonflybsd.org/cvsweb/src/sys/bus/firewire/fwdev.c
MISC http://www.kernelhacking.com/bsdadv1.txt
CONFIRM http://cvsweb.netbsd.org/bsdweb.cgi/src/sys/dev/ieee1394/fwdev.c
FREEBSD FreeBSD-SA-06:25
BID 21089
SECTRACK 1017344
SECUNIA 22917
XF freebsd-fwdev-integer-overflow(30347)