PT-2005-4814 · Blackberry · Qnx
Published
2005-12-08
·
Updated
2018-10-19
·
CVE-2005-4082
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
QNX version 4.25
Description
The dhcp.client program is setuid, which allows local users to modify the NIC configuration and conduct other attacks.
Recommendations
For QNX version 4.25, consider removing the setuid bit from the dhcp.client program to prevent local users from modifying the NIC configuration and conducting other attacks.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Qnx