OSVDB ID: 22961

Title: QNX Neutrino RTOS su First Parameter Local Overflow

Info

Disclosure

Feb 07, 2006

Discovery

Jun 04, 2004

Dates

Exploit

Unknown

Solution

Unknown

Description

A local overflow exists in QNX Neutrino RTOS. The 'su' binary fails to properly check user-supplied input as the first argument to the program resulting in a buffer overflow. With a specially crafted request, an attacker can cause the execution of arbitrary code with root priveleges.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Exploit: Exploit Rumored

Solution

Currently, there are no known upgrades or patches to correct this issue. It is possible to correct the flaw by implementing the following workaround: restrict access to the su binary

Products

QNX Software Systems

QNX Neutrino RTOS

6.2.0

References

Credit

  • Texonet - Texonet


Direct URL: http://osvdb.org/22961