First published: Tue Jan 20 2015(Updated: )
The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
illumos |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9491 is classified as a denial of service vulnerability due to a NULL pointer dereference.
To fix CVE-2014-9491, ensure that you are using an updated version of illumos that addresses this vulnerability.
CVE-2014-9491 affects the illumos operating system.
Yes, CVE-2014-9491 can be exploited by remote attackers to trigger a denial of service.
CVE-2014-9491 can cause a system panic due to a NULL pointer dereference.