PT-2002-2761 · Blackberry · Qnx
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2040
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
QNX realtime operating system (RTOS) versions 4.25 and 6.1.0
Description
The issue concerns the phrafx and phgrafx-startup programs in the QNX realtime operating system (RTOS), which do not properly drop privileges before executing the system command. This allows local users to execute arbitrary commands by modifying the
PATH environment variable to reference a malicious crttrap program.Recommendations
For QNX realtime operating system (RTOS) version 4.25, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For QNX realtime operating system (RTOS) version 6.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qnx