PT-2002-2761 · Blackberry · Qnx

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2040

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions QNX realtime operating system (RTOS) versions 4.25 and 6.1.0
Description The issue concerns the phrafx and phgrafx-startup programs in the QNX realtime operating system (RTOS), which do not properly drop privileges before executing the system command. This allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.
Recommendations For QNX realtime operating system (RTOS) version 4.25, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For QNX realtime operating system (RTOS) version 6.1.0, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2040

Affected Products

Qnx