Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2002-2407

Опубликовано: 31 дек. 2002
Источник: nvd
CVSS2: 6.9
EPSS Низкий

Описание

Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:qnx:rtos:6.2:*:*:*:*:*:*:*
cpe:2.3:a:qnx:rtos:6.2a:*:*:*:*:*:*:*

EPSS

Процентиль: 32%
0.00122
Низкий

6.9 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

Certain patches for QNX Neutrino realtime operating system (RTOS) 6.2.0 set insecure permissions for the files (1) /sbin/io-audio by OS Update Patch A, (2) /bin/shutdown, (3) /sbin/fs-pkg, and (4) phshutdown by QNX experimental patches, (5) cpim, (6) vpim, (7) phrelaycfg, and (8) columns, (9) othello, (10) peg, (11) solitaire, and (12) vpoker in the games pack 2.0.3, which allows local users to gain privileges by modifying the files before permissions are changed.

EPSS

Процентиль: 32%
0.00122
Низкий

6.9 Medium

CVSS2

Дефекты

CWE-264