PT-2009-4890 · Netbsd · Netbsd

Publicado

2009-07-16

·

Atualizado

2017-08-17

·

CVE-2009-2483

CVSS v2.0

4.9

Média

VetorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions NetBSD versions 4.0 through 4.0.1
Description The issue allows local users to cause a denial of service, resulting in a NULL pointer dereference and kernel panic. This can be achieved by using a malformed externalized plist in XML form that contains an undefined element.
Recommendations For NetBSD versions 4.0 through 4.0.1, consider restricting the use of externalized plists in XML form until a patch is available. As a temporary workaround, avoid using undefined elements in externalized plists to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2483

Produtos afetados

Netbsd