First published: Fri Jul 26 2002(Updated: )
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNX RTOS | =4.25 | |
Blackberry Qnx Neutrino Real-time Operating System | =4.25 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-0793 is considered a moderate severity vulnerability that allows local users to overwrite arbitrary files.
Local users can exploit CVE-2002-0793 by using specific command arguments in utilities such as monitor, dumper, and crttrap.
CVE-2002-0793 affects QNX RTOS 4.25 and Blackberry QNX Neutrino Real-time Operating System version 4.25.
The potential impacts of CVE-2002-0793 include unauthorized file modification and loss of system integrity.
To mitigate CVE-2002-0793, ensure users are restricted from accessing vulnerable command utilities and apply any available patches.