7.2
CVSSv2

CVE-2002-1239

Published: 12/11/2002 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.

Vulnerable Product Search on Vulmon Subscribe to Product

qnx rtos 6.2.0

Exploits

source: wwwsecurityfocuscom/bid/6146/info A vulnerability has been discovered in an application packager shipped with QNX RTOS It should be noted that the vulnerable packager is installed setuid root by default It has been reported that the packager fails to use absolute paths to execute system commands This could potentially allow an ...