Denial of Service Vulnerability in illumos by Joyent
CVE-2014-9491

Currently unrated

Key Information:

Vendor

Illumos

Status
Vendor
CVE Published:
20 January 2015

What is CVE-2014-9491?

A vulnerability in the devzvol_readdir function of the illumos operating system allows remote attackers to induce a denial of service by triggering a NULL pointer dereference. This can result in system panic and downtime. The flaw stems from a failure to verify the output of a strchr function call, potentially exposing systems to successful exploitation through unspecified vectors. Users of illumos should review the available patches and security advisories to mitigate this risk.

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.