PT-2006-1676 · Blackberry · Libap+2

Publicado

2006-02-09

·

Atualizado

2017-07-20

·

CVE-2006-0619

CVSS v2.0

4.6

Média

VetorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QNX Neutrino RTOS version 6.3.0
Description The issue is related to multiple stack-based buffer overflows that allow local users to execute arbitrary code. This can be achieved via long environment variables, specifically the ABLPATH or ABLANG variables in the libAP library, or a long PHOTON PATH environment variable to the setitem function in the libph library.
Recommendations For QNX Neutrino RTOS version 6.3.0, consider restricting the length of the ABLPATH, ABLANG, and PHOTON PATH environment variables to prevent buffer overflows. As a temporary workaround, restrict access to the libAP and libph libraries until a patch is available. Avoid using long environment variables in the affected libraries until the issue is resolved.

Correção

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2006-0619

Produtos afetados

Qnx Neutrino Rtos
Libap
Libph