CVE-2004-1391: Medium severity QNX RTOS vulnerability
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1391?
CVE-2004-1391 is considered a high severity vulnerability due to its potential to allow local users to execute arbitrary programs.
How do I fix CVE-2004-1391?
To fix CVE-2004-1391, users should ensure that the PATH environment variable is not modifiable by untrusted users and update to the latest version of QNX that addresses this vulnerability.
Who is affected by CVE-2004-1391?
CVE-2004-1391 affects local users of QNX RTP 6.1 and its subsequent versions.
What type of vulnerability is CVE-2004-1391?
CVE-2004-1391 is classified as an untrusted execution path vulnerability.
What can an attacker do with CVE-2004-1391?
An attacker exploiting CVE-2004-1391 can execute arbitrary programs on the system by manipulating the PATH environment variable.