Multiple QNX Local Buffer Overflow Vulnerabilities
BID:5000
Info
Multiple QNX Local Buffer Overflow Vulnerabilities
| Bugtraq ID: | 5000 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 12 2002 12:00AM |
| Updated: | Jun 12 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Egor Egorov <[email protected]>. |
| Vulnerable: |
QNX RTOS 4.25 |
| Not Vulnerable: | |
Discussion
Multiple QNX Local Buffer Overflow Vulnerabilities
QNX RTOS is a real-time operating system designed for use on embedded systems. It is distributed and maintained by QNX.
It has been discovered that the following programs are vulnerable to buffer overflows:
/bin/du
/bin/ex
/bin/find
/bin/lex
/bin/mkdir
/bin/rm
/bin/sample
/bin/serserv
/bin/tcpserv
/bin/termdef
/bin/time
/bin/unzip
/bin/use
/bin/wcc
/bin/wcc386
/bin/wd
/bin/wdisasm
/bin/which
/bin/wlib
/bin/wlink
/bin/wpp
/bin/wpp386
/bin/wprof
/bin/write
/bin/wstrip
Some but not all of these executables are setuid. Any vulnerable setuid executables may allow a local user to execute arbitrary code, and gain elevated privileges.
QNX RTOS is a real-time operating system designed for use on embedded systems. It is distributed and maintained by QNX.
It has been discovered that the following programs are vulnerable to buffer overflows:
/bin/du
/bin/ex
/bin/find
/bin/lex
/bin/mkdir
/bin/rm
/bin/sample
/bin/serserv
/bin/tcpserv
/bin/termdef
/bin/time
/bin/unzip
/bin/use
/bin/wcc
/bin/wcc386
/bin/wd
/bin/wdisasm
/bin/which
/bin/wlib
/bin/wlink
/bin/wpp
/bin/wpp386
/bin/wprof
/bin/write
/bin/wstrip
Some but not all of these executables are setuid. Any vulnerable setuid executables may allow a local user to execute arbitrary code, and gain elevated privileges.
Exploit / POC
Multiple QNX Local Buffer Overflow Vulnerabilities
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Multiple QNX Local Buffer Overflow Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple QNX Local Buffer Overflow Vulnerabilities
References:
References: