2009-07-16 18:30:00 2017-08-17 03:30:47

libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.

Vector

LOCAL

Complexity

LOW

Authentication

NONE

Confidentiality

NONE

Integrity

NONE

Availability

COMPLETE
Advisory Patch Confirmed Link
netbsd-xml-dos(51311)
1022431
35466
NetBSD-SA2009-003