CVE-2002-2040

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/12/2002
Last modified:
20/11/2024

Description

The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:qnx:rtos:4.25:*:*:*:*:*:*:*
cpe:2.3:a:qnx:rtos:6.1.0:*:*:*:*:*:*:*