PT-2002-2761 · Blackberry · Qnx

Publicado

2002-12-31

·

Atualizado

2008-09-05

·

CVE-2002-2040

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNX realtime operating system (RTOS) versions 4.25 and 6.1.0
Description The issue concerns the phrafx and phgrafx-startup programs in the QNX realtime operating system (RTOS), which do not properly drop privileges before executing the system command. This allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.
Recommendations For QNX realtime operating system (RTOS) version 4.25, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For QNX realtime operating system (RTOS) version 6.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-2040

Produtos afetados

Qnx