7.2

CVE-2002-2040

Exploit
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
QnxRtos Version4.25
QnxRtos Version6.1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.08% 0.608
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://online.securityfocus.com/archive/1/275218
http://www.iss.net/security_center/static/9257.php
http://www.securityfocus.com/bid/4915
Exploit
http://www.securityfocus.com/bid/4916
Exploit