PT-2004-2305 · Qnx · Qnx Rtp

Publicado

2004-12-31

·

Atualizado

2017-07-11

·

CVE-2004-1390

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: QNX RTP version 6.1
Description: The issue is related to multiple buffer overflows in the PPPoE daemon. These overflows can be triggered by a long argument to various flags, including the -F flag, name, en, upscript, downscript, retries, timeout, scriptdetach, noscript, nodetach, remote mac, or local mac flags, allowing remote attackers to execute arbitrary code.
Recommendations: For QNX RTP version 6.1, consider disabling the PPPoE daemon until a patch is available to prevent potential exploitation. Restrict access to the flags that can trigger the buffer overflows to minimize the risk of arbitrary code execution.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2004-1390

Produtos afetados

Qnx Rtp