PT-2006-1676 · Blackberry · Libap+2
Published
2006-02-09
·
Updated
2017-07-20
·
CVE-2006-0619
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
QNX Neutrino RTOS version 6.3.0
Description
The issue is related to multiple stack-based buffer overflows that allow local users to execute arbitrary code. This can be achieved via long environment variables, specifically the
ABLPATH or ABLANG variables in the libAP library, or a long PHOTON PATH environment variable to the setitem function in the libph library.Recommendations
For QNX Neutrino RTOS version 6.3.0, consider restricting the length of the
ABLPATH, ABLANG, and PHOTON PATH environment variables to prevent buffer overflows. As a temporary workaround, restrict access to the libAP and libph libraries until a patch is available. Avoid using long environment variables in the affected libraries until the issue is resolved.Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Qnx Neutrino Rtos
Libap
Libph