vendor:
QNX Neutrino RTOS
by:
Luigi Auriemma
8,8
CVSS
HIGH
Stack Overflow and Buffer Overflow
119, 120
CWE
Product Name: QNX Neutrino RTOS
Affected Version From: Current
Affected Version To: Current
Patch Exists: Yes
Related CWE: N/A
CPE: a:qnx:qnx_neutrino_rtos
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: QNX Neutrino RTOS and Windows
2012
QNX phrelay/phindows/phditto Vulnerabilities
The BPE (byte pair encoding) compression uses two stack buffers of 256 bytes called 'left' and 'right'. The bpe_decompress function used in all the client/server programs of this protocol is affected by a stack based buffer-overflow caused by the lack of checks on the data sequentially stored in these two buffers. Buffer-overflow affecting phrelay in the handling of the device file specified by the client as existing Photon session.
Mitigation:
Update to the latest version of QNX phrelay/phindows/phditto