The devzvol_readdir function in illumos does not check the return value of a strchr call, which allows remote attackers to cause a denial of service (NULL pointer dereference and panic) via unspecified vectors.
CVSS Details
- CVSS 3.1 Base Score: 7.5
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Oracle Solaris | — | Upgrade consolidation/osnet/osnet-incorporation to version 0.5.11-0.175.3.0.0.30.0 on Solaris 11.3Upgrade system/kernel to version 0.5.11-0.175.2.4.0.5.2 on Solaris 11.2 | May 29, 2017 | Jan 20, 2015 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub