First published: Thu Jul 16 2009(Updated: )
libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetBSD NetBSD | =4.0 | |
NetBSD NetBSD | =4.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-2483 is considered a high severity vulnerability due to its potential to cause a denial of service through kernel panic.
To mitigate CVE-2009-2483, upgrade your system to a version of NetBSD that is not vulnerable, specifically later than 4.0.1.
CVE-2009-2483 affects local users on NetBSD versions 4.0 and 4.0.1.
CVE-2009-2483 enables a denial of service attack through a malformed externalized plist that leads to a NULL pointer dereference.
CVE-2009-2483 affects the proplib library, specifically the prop_object.c file in NetBSD.