20021108 iDEFENSE Security Advisory 11.08.02b: Non-Explicit Path Vulnerability in QNX Neutrino RTOSmailing list
http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0066.html CVE-2002-1239
QNX RTOS 6.2 - Application Packager Non-Explicit Path Execution
Record summary
CVE-2002-1239 has a selected CVSS score of 7.2; EIP currently links 1 catalogued exploit.
Description
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised privileges, which allows local users to gain privileges by modifying the PATH to point to a malicious cp program.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQNX RTOS 6.2 - Application Packager Non-Explicit Path ExecutionExploitDB exploitby TexonetNot analyzed1 file
References
620021108 iDEFENSE Security Advisory 11.08.02b: Non-Explicit Path Vulnerability in QNX Neutrino RTOSmailing list
http://marc.info/?l=bugtraq&m=103679043232178&w=2 idefense.com
http://www.idefense.com/advisory/11.08.02b.txt qnx-rtos-gain-privileges(10564)vdb entry
http://www.iss.net/security_center/static/10564.php 6146vdb entry
http://www.securityfocus.com/bid/6146 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2002-1239