20140311 Medium severity flaw in BlackBerry QNX Neutrino RTOSmailing list
http://seclists.org/bugtraq/2014/Mar/66 CVE-2014-2534
QNX 6.4.x/6.5.x pppoectl - Information Disclosure
Record summary
CVE-2014-2534 has a selected CVSS score of 4.9; EIP currently links 1 catalogued exploit.
Description
/sbin/pppoectl in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to obtain sensitive information by reading "bad parameter" lines in error messages, as demonstrated by reading the root password hash in /etc/shadow.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBQNX 6.4.x/6.5.x pppoectl - Information DisclosureExploitDB exploitby cenobyteNot analyzed1 file
References
620140313 Re: Medium severity flaw in BlackBerry QNX Neutrino RTOSmailing list
http://seclists.org/bugtraq/2014/Mar/88 20140313 Re: Medium severity flaw in BlackBerry QNX Neutrino RTOSmailing list
http://seclists.org/fulldisclosure/2014/Mar/124 20140312 Medium severity flaw in BlackBerry QNX Neutrino RTOSmailing list
http://seclists.org/fulldisclosure/2014/Mar/98 32156exploit
http://www.exploit-db.com/exploits/32156 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2014-2534