PT-2013-3873 · Blackberry · Blackberry Qnx Neutrino Rtos+1
Published
2013-07-12
·
Updated
2013-07-15
·
CVE-2013-2687
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
BlackBerry QNX Neutrino RTOS versions through 6.5.0 SP1
QNX Momentics Tool Suite versions through 6.5.0 SP1
Description
The issue is a stack-based buffer overflow in the
bpe decompress function, allowing remote attackers to cause a denial of service or possibly execute arbitrary code via crafted packets to TCP port 4868, which is the API Endpoint: 'TCP port 4868'.Recommendations
For BlackBerry QNX Neutrino RTOS versions through 6.5.0 SP1, update to a version that fixes the
bpe decompress function issue.
For QNX Momentics Tool Suite versions through 6.5.0 SP1, update to a version that fixes the bpe decompress function issue.Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Blackberry Qnx Neutrino Rtos
Qnx Momentics Tool Suite