Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Integer signedness error in the fw_ioctl (FW_IOCTL) function in the FireWire (IEEE-1394) drivers (dev/firewire/fwdev.c) in various BSD kernels, including DragonFlyBSD, FreeBSD 5.5, MidnightBSD 0.1-CURRENT before 20061115, NetBSD-current before 20061116, NetBSD-4 before 20061203, and TrustedBSD, allows local users to read arbitrary memory contents via certain negative values of crom_buf->len in an FW_GCROM command. NOTE: this issue has been labeled as an integer overflow, but it is more like an integer signedness error.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
多个BSD厂商FireWire IOCTL本地整数溢出漏洞
Vulnerability Description
在各个BSD内核,包括DragonFlyBSD、FreeBSD、MidnightBSD 0.1-CURRENT 、NetBSD-current、NetBSD-4和TrustedBSD版本中的FireWire (IEEE-1394)驱动程序(dev/firewire/fwdev.c)的fw_ioctl(FW_IOCTL)函数中存在整数符号错误,本地用户可以通过在一个FW_GCROM命令中的crom_buf->len的某些负数值来读取任意内存的内容。
CVSS Information
N/A
Vulnerability Type
N/A