CVE-2014-9491 Information

Description

The devzvol_readdir function in illumos does not check the return value of a strchr call which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.

Reference

http://seclists.org/oss-sec/2015/q1/27 https://exchange.xforce.ibmcloud.com/vulnerabilities/99686 https://github.com/illumos/illumos-gate/commit/d65686849024838243515b5c40ae2c479460b4b5 https://www.illumos.org/issues/5421

Share on: