Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2004-1683

Overview

Vulnerability Score 3.7 3.7
CVE Id CVE-2004-1683
Last Modified 05 Sep 2008 04:42:04
Published 13 Sep 2004 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity HIGH
Authentication NONE

CVE-2004-1683

Summary

A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.

Vulnerable Systems


References

XF - qnx-rtp-crttrap-race-condition(17345)

BID - 11165

BUGTRAQ - 20040913 [RLSA_04-2004] QNX crrtrap possible race condition vulnerability


Last Updated: 27 May 2016 10:39:08