PT-2002-2761 · Blackberry · Qnx
Publicado
2002-12-31
·
Atualizado
2008-09-05
·
CVE-2002-2040
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QNX realtime operating system (RTOS) versions 4.25 and 6.1.0
Description
The issue concerns the phrafx and phgrafx-startup programs in the QNX realtime operating system (RTOS), which do not properly drop privileges before executing the system command. This allows local users to execute arbitrary commands by modifying the
PATH environment variable to reference a malicious crttrap program.Recommendations
For QNX realtime operating system (RTOS) version 4.25, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For QNX realtime operating system (RTOS) version 6.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Qnx