CVE-2002-2040
Published Dec 31, 2002
Last updated 16 years ago
Overview
- Description
- The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly drop privileges before executing the system command, which allows local users to execute arbitrary commands by modifying the PATH environment variable to reference a malicious crttrap program.
- Source
- cve@mitre.org
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 7.2
- Impact score
- 10
- Exploitability score
- 3.9
- Vector string
- AV:L/AC:L/Au:N/C:C/I:C/A:C
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:qnx:rtos:4.25:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "F05ACD69-8EEF-4D6B-A825-92051DFE9C4D" }, { "criteria": "cpe:2.3:a:qnx:rtos:6.1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "C37EB0A5-8A16-42A1-B229-BB223AAF9AA7" } ], "operator": "OR" } ] } ]