vendor:
RTOS Packager
by:
SecurityFocus
7.2
CVSS
HIGH
Path Manipulation
22
CWE
Product Name: RTOS Packager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
QNX RTOS Packager Vulnerability
It has been reported that the packager fails to use absolute paths to execute system commands. This could potentially allow an attacker to trick the program into running a trojaned binary. Because the vulnerable packager is installed setuid root by default, this could allow a local attacker to take complete control over a system.
Mitigation:
Ensure that absolute paths are used when executing system commands.