header-logo
Suggest Exploit
vendor:
Photon MicroGUI
by:
SecurityFocus
7.5
CVSS
HIGH
Multiple Buffer Overflow Vulnerabilities
119
CWE
Product Name: Photon MicroGUI
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: o:qnx:photon_microgui
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2003

QNX Photon MicroGUI Multiple Buffer Overflow Vulnerabilities

Multiple buffer overflow vulnerabilities exist in QNX Photon MicroGUI utilities due to a failure of the affected applications to validate user-supplied string lengths before copying them into finite process buffers. An attacker may leverage these issues to execute arbitrary code on the affected system within the context of the vulnerable applications; the applications are typically setuid applications.

Mitigation:

Upgrade to the latest version of QNX Photon MicroGUI.
Source

Exploit-DB raw data:

source: https://www.securityfocus.com/bid/11164/info
  
Reportedly QNX Photon MicroGUI is affected by multiple buffer overflow vulnerabilities in MicroGUI utilities. These issues are due to a failure of the affected applications to validate user-supplied string lengths before copying them into finite process buffers.
  
An attacker may leverage these issues to execute arbitrary code on the affected system within the context of the vulnerable applications; the applications are typically setuid applications.

$ /usr/photon/bin/pkg-installer -s AAAAA[...]