Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 492734 - sys-freebsd/freebsd-sources: Information leak (CVE-2013-{6832,6833,6834})
Summary: sys-freebsd/freebsd-sources: Information leak (CVE-2013-{6832,6833,6834})
Status: RESOLVED WONTFIX
Alias: None
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Security
URL:
Whiteboard: ~4 [noglsa cve]
Keywords:
Depends on:
Blocks:
 
Reported: 2013-11-27 21:42 UTC by GLSAMaker/CVETool Bot
Modified: 2016-11-26 01:07 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description GLSAMaker/CVETool Bot gentoo-dev 2013-11-27 21:42:50 UTC
CVE-2013-6834 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6834):
  The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD
  10 and earlier does not validate a certain size parameter, which allows
  local users to obtain sensitive information from kernel memory via a crafted
  ioctl call.

CVE-2013-6833 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6833):
  The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in
  FreeBSD 10 and earlier does not validate a certain size parameter, which
  allows local users to obtain sensitive information from kernel memory via a
  crafted ioctl call.

CVE-2013-6832 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2013-6832):
  The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in
  the kernel in FreeBSD 10 and earlier does not properly initialize a certain
  data structure, which allows local users to obtain sensitive information
  from kernel memory via a crafted ioctl call.
Comment 1 Naohiro Aota gentoo-dev 2013-11-30 13:22:42 UTC
9.1 seems not to be affected.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2016-11-26 01:06:44 UTC
FreeBSD sources are not supported by the security team.