PT-2004-2589 · Qnx · Qnx Rtp

Julio Cesar Fort

·

Published

2004-09-13

·

Updated

2017-07-11

·

CVE-2004-1683

CVSS v2.0

3.7

Low

VectorAV:L/AC:H/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions QNX RTP version 6.1
Description A race condition issue exists, allowing local users to gain privileges. This is achieved by modifying the PATH environment variable to reference a malicious io-graphics program before it is executed by crrtrap.
Recommendations For QNX RTP version 6.1, consider restricting modifications to the PATH environment variable to prevent malicious references to io-graphics programs until a fix is available. As a temporary workaround, monitor and control the execution of crrtrap to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-1683

Affected Products

Qnx Rtp