QNX RTOS phgrafxPrivilege Escalation Vulnerability
BID:4915
Info
QNX RTOS phgrafxPrivilege Escalation Vulnerability
| Bugtraq ID: | 4915 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 03 2002 12:00AM |
| Updated: | Jun 03 2002 12:00AM |
| Credit: | Credited to <[email protected]>. |
| Vulnerable: |
QNX RTOS 6.1 QNX RTOS 4.25 |
| Not Vulnerable: | |
Discussion
QNX RTOS phgrafxPrivilege Escalation Vulnerability
The QNX phgrafx utility is prone to an issue which may make it possible for local attackers to escalate privileges. This issue is due to unsafe use of the system() function to invoke other programs. This vulnerability may be trivially exploited to gain root privileges.
The QNX phgrafx utility is prone to an issue which may make it possible for local attackers to escalate privileges. This issue is due to unsafe use of the system() function to invoke other programs. This vulnerability may be trivially exploited to gain root privileges.
Exploit / POC
QNX RTOS phgrafxPrivilege Escalation Vulnerability
The following exploit was provided by <[email protected]>:
The following exploit was provided by <[email protected]>:
Solution / Fix
QNX RTOS phgrafxPrivilege Escalation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.