vendor:
pkg-installer
by:
badc0ded.com
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: pkg-installer
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: QNX
2002
QNX pkg-installer root exploit
It has been reported that the pkg-installer utility for QNX is vulnerable to a buffer overflow condition. The vulnerability is a result of an unbounded string copy of the argument to the "-U" commandline option of pkg-installer to a local buffer.
Mitigation:
Input validation should be used to prevent buffer overflow attacks.