PT-2002-2760 · Qnx · Qnx Rtos

Publicado

2002-12-31

·

Atualizado

2016-10-18

·

CVE-2002-2039

CVSS v2.0

2.1

Baixa

VetorAV:L/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions QNX realtime operating system (RTOS) versions 4.25 through 6.1.0
Description The issue allows local users to obtain sensitive information from core dump files by sending the SIGSERV signal, which is related to an invalid memory reference, to /bin/su in the affected QNX RTOS versions.
Recommendations For QNX RTOS versions 4.25 through 6.1.0, consider restricting access to the /bin/su command until a fix is available. As a temporary workaround, avoid using the /bin/su command with signals that may cause an invalid memory reference, such as SIGSERV, until the issue is resolved.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2039

Produtos afetados

Qnx Rtos