Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fqc4-8m96-pvh3

Опубликовано: 30 апр. 2022
Источник: github
Github: Не прошло ревью

Описание

The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.

The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.

EPSS

Процентиль: 54%
0.00309
Низкий

Связанные уязвимости

nvd
около 23 лет назад

The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.

EPSS

Процентиль: 54%
0.00309
Низкий