libprop/prop_object.c in proplib in NetBSD 4.0 and 4.0.1 allows local users to cause a denial of service (NULL pointer dereference and kernel panic) via a malformed externalized plist (XML form) containing an undefined element.
Weaknesses in this category are related to improper calculation or conversion of numbers.
Link | Tags |
---|---|
http://secunia.com/advisories/35556 | third party advisory vendor advisory |
http://www.securityfocus.com/bid/35466 | vdb entry |
https://exchange.xforce.ibmcloud.com/vulnerabilities/51311 | vdb entry |
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2009-003.txt.asc | vendor advisory |
http://osvdb.org/55285 | vdb entry |
http://www.securitytracker.com/id?1022431 | vdb entry |