CVE-2002-2041
QNX RTOS 6.1.0 - Local Buffer Overflow via ABLANG Environment Variable or pkg-installer -u Option
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2002-2041. PoCs published by badc0ded.
AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the QNX pkg-installer utility via the '-U' command-line option. It uses a shellcode payload to achieve remote code execution by overwriting the return address with a hardcoded system() address.
Description
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1) a long ABLANG environment variable in phlocale or (2) a long -u option to pkg-installer.
Exploits (2)
This exploit targets a buffer overflow vulnerability in the QNX pkg-installer utility via the '-U' command-line option. It uses a shellcode payload to achieve remote code execution by overwriting the return address with a hardcoded system() address.
This exploit targets a buffer overflow in QNX phlocale via the ABLANG environment variable. It uses shellcode to spawn a root shell by overwriting the return address with a system() call.