Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Multiple buffer overflows in QNX 4.25 may allow local users to execute arbitrary code via long command line arguments to (1) sample, (2) ex, (3) du, (4) find, (5) lex, (6) mkdir, (7) rm, (8) serserv, (9) tcpserv, (10) termdef, (11) time, (12) unzip, (13) use, (14) wcc, (15) wcc386, (16) wd, (17) wdisasm, (18) which, (19) wlib, (20) wlink, (21) wpp, (22) wpp386, (23) wprof, (24) write, or (25) wstrip.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
QNX多个本地缓冲区溢出漏洞
Vulnerability Description
QNX RTOS是一款设计用于嵌入系统的实时操作系统,由QNX分发和维护。 QNX RTOS中多个程序存在漏洞,本地攻击者利益利用这些漏洞进行缓冲区溢出攻击。 QNX RTOS中有漏洞的多个程序多数以setuid root属性默认安装,这些程序对用户提交的参数边界长度缺少正确的检查,攻击者可以进行缓冲区溢出攻击,精心构建参数数据可能导致以root权限执行任意指令。 包含漏洞的程序如下所示: /bin/du /bin/ex /bin/find /bin/lex /bin/mkdir /bin/rm /bin
CVSS Information
N/A
Vulnerability Type
N/A