6.2
CVSSv2

CVE-2006-0620

Published: 09/02/2006 Updated: 20/07/2017
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 625
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.

Vulnerable Product Search on Vulmon Subscribe to Product

qnx rtos 6.2.1a

qnx rtos 6.2.1b

qnx rtos 6.2.1

Exploits

#!/bin/sh # word, exploit for wwwidefensecom/intelligence/vulnerabilities/displayphp?id=383 # greetings and salutations from wwwlortdk # kokanin@dtors 18/10/2003 # $ cksum /usr/photon/bin/phfont # 4123428723 30896 /usr/photon/bin/phfont # $ uname -a # QNX localhost 621 2003/01/08-14:50:46est x86pc x86 cat > phfontphfc <&l ...