CVE-2002-2039
QNX RTOS 4.25 and 6.1.0 - Information Disclosure via /bin/su Core Dump
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2002-2039. PoCs published by badc0ded.
AI-analyzed exploit summary This exploit leverages a vulnerability in the 'su' utility for QNX RTOS where sending a SIGSEGV signal causes a world-readable core dump. The attacker can then extract sensitive information, such as the root password hash, from the core file.
Description
/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from core dump files by sending the SIGSERV (invalid memory reference) signal.
Exploits (1)
This exploit leverages a vulnerability in the 'su' utility for QNX RTOS where sending a SIGSEGV signal causes a world-readable core dump. The attacker can then extract sensitive information, such as the root password hash, from the core file.