QNX Phgrafx Local Buffer Overflow Vulnerability
BID:15619
Info
QNX Phgrafx Local Buffer Overflow Vulnerability
| Bugtraq ID: | 15619 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 29 2005 12:00AM |
| Updated: | Nov 29 2005 12:00AM |
| Credit: | Discovery is credited to pasquale minervini <[email protected]>. |
| Vulnerable: |
QNX RTOS 6.3 |
| Not Vulnerable: | |
Discussion
QNX Phgrafx Local Buffer Overflow Vulnerability
QNX phgrafx is prone to a local buffer overflow vulnerability.
Reports indicate that the affected utility has setuid-superuser privileges, which allows a successful attack to result in arbitrary machine code execution with superuser privileges.
QNX 6.3.0 is reportedly vulnerable, however, it is possible that other versions are affected as well.
QNX phgrafx is prone to a local buffer overflow vulnerability.
Reports indicate that the affected utility has setuid-superuser privileges, which allows a successful attack to result in arbitrary machine code execution with superuser privileges.
QNX 6.3.0 is reportedly vulnerable, however, it is possible that other versions are affected as well.
Exploit / POC
QNX Phgrafx Local Buffer Overflow Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
QNX Phgrafx Local Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
QNX Phgrafx Local Buffer Overflow Vulnerability
References:
References:
- QNX Homepage (QNX Software Systems Ltd.)
- possible privilege escalation on QNX Neutrino 6.3.0 (pasquale minervini
)