QNX Multiple Local Privilege Escalation and Denial Of Service Vulnerabilities
BID:16539
Info
QNX Multiple Local Privilege Escalation and Denial Of Service Vulnerabilities
| Bugtraq ID: | 16539 |
| Class: | Unknown |
| CVE: |
CVE-2005-1528 CVE-2006-0618 CVE-2006-0619 CVE-2006-0620 CVE-2006-0621 CVE-2006-0623 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 07 2006 12:00AM |
| Updated: | Jul 05 2016 09:38PM |
| Credit: | The discoverers of the crttrap, gdb, and the rc.local issues wish to remain anonymous. The fontsleuth issue was discovered by iDefense Labs. Filipe Balestra discovered the libAP and libph issues. Knud Hojgaard discovered the phfont and phgrafx issues. Texo |
| Vulnerable: |
QNX RTOS 6.3 QNX RTOS 6.2.1 QNX RTOS 6.2 |
| Not Vulnerable: | |
Discussion
QNX Multiple Local Privilege Escalation and Denial Of Service Vulnerabilities
QNX is susceptible to multiple local vulnerabilities. These issues include multiple buffer-overflow vulnerabilities, a format-string vulnerability, an insecure library-path vulnerability, insecure default-directory-permission vulnerability, and a denial-of-service vulnerability.
These issues allow local attackers to execute arbitrary machine code and commands with superuser privileges, facilitating the complete compromise of affected computers. Attackers may also crash affected computers, denying service to legitimate users.
QNX version 6.2.0, 6.2.1, and 6.3 are affected by these issues; earlier versions may also be affected.
QNX is susceptible to multiple local vulnerabilities. These issues include multiple buffer-overflow vulnerabilities, a format-string vulnerability, an insecure library-path vulnerability, insecure default-directory-permission vulnerability, and a denial-of-service vulnerability.
These issues allow local attackers to execute arbitrary machine code and commands with superuser privileges, facilitating the complete compromise of affected computers. Attackers may also crash affected computers, denying service to legitimate users.
QNX version 6.2.0, 6.2.1, and 6.3 are affected by these issues; earlier versions may also be affected.
Exploit / POC
QNX Multiple Local Privilege Escalation and Denial Of Service Vulnerabilities
Some of these issues do not require exploits.
To exploit the denial-of-service vulnerability, the following command is reportedly sufficient:
echo -e "break *0xb032d59fnrncontncont" | gdb gdb
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Some of these issues do not require exploits.
To exploit the denial-of-service vulnerability, the following command is reportedly sufficient:
echo -e "break *0xb032d59fnrncontncont" | gdb gdb
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
QNX Multiple Local Privilege Escalation and Denial Of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
QNX Multiple Local Privilege Escalation and Denial Of Service Vulnerabilities
References:
References:
- Advisory: 02.07.06 - QNX Neutrino RTOS crttrap Arbitrary Library Loading Vulnera (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS fontsleuth Command Format String Vulnerab (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS libAp ABLPATH Buffer Overflow Vulnerabili (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS libph PHOTON_PATH Buffer Overflow Vulnera (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS passwd Command Buffer Overflow (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS phfont Race Condition Vulnerability (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS phgrafx Command Buffer Overflow (iDefense)
- Advisory: 02.07.06 - QNX Neutrino RTOS su Command Buffer Overflow (iDefense)
- Advisory: 02.07.06 - QNX RTOS 6.3.0 Local Denial of Service Vulnerability (iDefense)
- Advisory: 02.07.06 - QNX RTOS 6.3.0 rc.local Insecure File Permissions Vulnerabi (iDefense)
- QNX Homepage (QNX Software Systems Ltd.)