CVE-2014-9491: Null Pointer Dereference
Published Jan 20, 2015
·Updated
The devzvolreaddir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.
Affected Software
1 affected component
illumos Illumos
Event History
Jan 20, 2015
CVE Published
via MITRE·03:00 PM
Data Sourced
via MITRE·03:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-9491?
CVE-2014-9491 is classified as a denial of service vulnerability due to a NULL pointer dereference.
2
How do I fix CVE-2014-9491?
To fix CVE-2014-9491, ensure that you are using an updated version of illumos that addresses this vulnerability.
3
What software is affected by CVE-2014-9491?
CVE-2014-9491 affects the illumos operating system.
4
Can CVE-2014-9491 allow for remote attacks?
Yes, CVE-2014-9491 can be exploited by remote attackers to trigger a denial of service.
5
What kind of denial of service does CVE-2014-9491 cause?
CVE-2014-9491 can cause a system panic due to a NULL pointer dereference.