CVE-2013-6833 Information

Description

The qls_eioctl function in sys/dev/qlxge/qls_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.

Reference

http://archives.neohapsis.com/archives/fulldisclosure/2013-11/0107.html

Share on: