Unchecked strchr Call in illumos' devzvol_readdir Function Allows for Denial of Service

Unchecked strchr Call in illumos' devzvol_readdir Function Allows for Denial of Service

CVE-2014-9491 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:N/A:P

The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.

Learn more about our Web Application Penetration Testing UK.