CVE-2013-6832

The nand_ioctl function in sys/dev/nand/nand_geom.c in the nand driver in the kernel in FreeBSD 10 and earlier does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted ioctl call.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.9 UNKNOWN
LOCAL
LOW
AV:L/AC:L/Au:N/C:C/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 17%
VendorProductVersion
freebsdfreebsd
𝑥
≤ 10.0
freebsdfreebsd
0.4_1:_1
freebsdfreebsd
1.0
freebsdfreebsd
1.1
freebsdfreebsd
1.1.5
freebsdfreebsd
1.1.5.1
freebsdfreebsd
1.2
freebsdfreebsd
1.5
freebsdfreebsd
2.0
freebsdfreebsd
2.0.1
freebsdfreebsd
2.0.5
freebsdfreebsd
2.1
freebsdfreebsd
2.1.0
freebsdfreebsd
2.1.5
freebsdfreebsd
2.1.6
freebsdfreebsd
2.1.6.1
freebsdfreebsd
2.1.7
freebsdfreebsd
2.1.7.1
freebsdfreebsd
2.2
freebsdfreebsd
2.2.1
freebsdfreebsd
2.2.2
freebsdfreebsd
2.2.3
freebsdfreebsd
2.2.4
freebsdfreebsd
2.2.5
freebsdfreebsd
2.2.6
freebsdfreebsd
2.2.7
freebsdfreebsd
2.2.8
freebsdfreebsd
3.0
freebsdfreebsd
3.1
freebsdfreebsd
3.2
freebsdfreebsd
3.3
freebsdfreebsd
3.4
freebsdfreebsd
3.5
freebsdfreebsd
3.5.1
freebsdfreebsd
4.0
freebsdfreebsd
4.1
freebsdfreebsd
4.1.1
freebsdfreebsd
4.2
freebsdfreebsd
4.3
freebsdfreebsd
4.4
freebsdfreebsd
4.5
freebsdfreebsd
4.6
freebsdfreebsd
4.6.2
freebsdfreebsd
4.7
freebsdfreebsd
4.8
freebsdfreebsd
4.9
freebsdfreebsd
4.10
freebsdfreebsd
4.11
freebsdfreebsd
5.0
freebsdfreebsd
5.1
freebsdfreebsd
5.2
freebsdfreebsd
5.2.1
freebsdfreebsd
5.3
freebsdfreebsd
5.4
freebsdfreebsd
5.5
freebsdfreebsd
6.0
freebsdfreebsd
6.1
freebsdfreebsd
6.2
freebsdfreebsd
6.3
freebsdfreebsd
6.4
freebsdfreebsd
7.0
freebsdfreebsd
7.1
freebsdfreebsd
7.2
freebsdfreebsd
7.3
freebsdfreebsd
7.4
freebsdfreebsd
8.0
freebsdfreebsd
8.1
freebsdfreebsd
8.2
freebsdfreebsd
8.3
freebsdfreebsd
8.4
freebsdfreebsd
9.0
freebsdfreebsd
9.1
freebsdfreebsd
9.2
𝑥
= Vulnerable software versions