CVE-2002-0793
Severity CVSS v4.0:
Pending analysis
Type:
CWE-59
Link Following
Publication date:
12/08/2002
Last modified:
20/11/2024
Description
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:blackberry:qnx_neutrino_real-time_operating_system:4.25:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0292.html
- http://www.iss.net/security_center/static/9231.php
- http://www.securityfocus.com/bid/4901
- http://www.securityfocus.com/bid/4902
- http://www.securityfocus.com/bid/4903
- http://www.securityfocus.com/bid/4904
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9232
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9233
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9234
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0292.html
- http://www.iss.net/security_center/static/9231.php
- http://www.securityfocus.com/bid/4901
- http://www.securityfocus.com/bid/4902
- http://www.securityfocus.com/bid/4903
- http://www.securityfocus.com/bid/4904
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9232
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9233
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9234