2.1
CVSSv2

CVE-2002-2039

Published: 31/12/2002 Updated: 18/10/2016
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
VMScore: 215
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.

Vulnerable Product Search on Vulmon Subscribe to Product

qnx rtos 4.25

qnx rtos 6.1.0

Exploits

source: wwwsecurityfocuscom/bid/4914/info It has been reported that the 'su' utility for QNX RTOS accepts the SIGSEGV signal and dumps a world readable core file An attacker is able to analyze the core file and obtain very sensitive information It is very probable that this is a kernel-based vulnerability affecting not only 'su', but o ...