CVE-2002-2040
N/A
N/A
Summary
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/4916
- http://www.securityfocus.com/bid/4915
- http://online.securityfocus.com/archive/1/275218
- http://www.iss.net/security_center/static/9257.php
References
- http://www.securityfocus.com/bid/4916
- http://www.securityfocus.com/bid/4915
- http://online.securityfocus.com/archive/1/275218
- http://www.iss.net/security_center/static/9257.php
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.