#VU42346 Input validation error in FreeBSD - CVE-2013-6834
Published: November 21, 2013 / Updated: August 10, 2020
FreeBSD
FreeBSD Foundation
Description
The vulnerability allows a remote non-authenticated attacker to gain access to sensitive information.
The ql_eioctl function in sys/dev/qlxgbe/ql_ioctl.c in the kernel in FreeBSD 10 and earlier does not validate a certain size parameter, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.