CVE-2002-2039

QNX RTOS 4.25 and 6.1.0 - Information Disclosure via /bin/su Core Dump

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-2039. PoCs published by badc0ded.

AI-analyzed exploit summary This exploit leverages a vulnerability in the 'su' utility for QNX RTOS where sending a SIGSEGV signal causes a world-readable core dump. The attacker can then extract sensitive information, such as the root password hash, from the core file.

Description

/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.

Exploits (1)

exploitdb WORKING POC VERIFIED
by badc0ded · textlocallinux
https://www.exploit-db.com/exploits/21502

This exploit leverages a vulnerability in the 'su' utility for QNX RTOS where sending a SIGSEGV signal causes a world-readable core dump. The attacker can then extract sensitive information, such as the root password hash, from the core file.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: QNX RTOS 'su' utility
No auth needed
Prerequisites: Access to a system running QNX RTOS · Ability to execute commands on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/4914
Third Party Advisory vdb-entry x_refsource_xf
http://www.iss.net/security_center/static/9256.php
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=102312549511726&w=2

Scores

EPSS 0.0084
EPSS Percentile 53.1%

Details

Status published
Products (2)
qnx/rtos 4.25
qnx/rtos 6.1.0
Published Dec 31, 2002
Tracked Since Feb 18, 2026