namei in FreeBSD 9.1 through 10.1-RC2 allows remote attackers to cause a denial of service (memory exhaustion) via vectors that trigger a sandboxed process to look up a large number of nonexistent path names.
Weaknesses in this category are related to improper management of system resources.
Link | Tags |
---|---|
http://www.debian.org/security/2014/dsa-3070 | vendor advisory |
http://secunia.com/advisories/62218 | third party advisory |
https://www.freebsd.org/security/advisories/FreeBSD-SA-14:22.namei.asc | patch vendor advisory |
http://www.securitytracker.com/id/1031100 | vdb entry |