PT-2004-2589 · Qnx · Qnx Rtp
Julio Cesar Fort
·
Published
2004-09-13
·
Updated
2017-07-11
·
CVE-2004-1683
CVSS v2.0
3.7
Low
| Vector | AV:L/AC:H/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
QNX RTP version 6.1
Description
A race condition issue exists, allowing local users to gain privileges. This is achieved by modifying the
PATH environment variable to reference a malicious io-graphics program before it is executed by crrtrap.Recommendations
For QNX RTP version 6.1, consider restricting modifications to the
PATH environment variable to prevent malicious references to io-graphics programs until a fix is available. As a temporary workaround, monitor and control the execution of crrtrap to minimize the risk of exploitation.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qnx Rtp