First published: Sun Aug 15 2004(Updated: )
Format string vulnerability in QNX 6.1 FTP client allows remote authenticated users to gain group bin privileges via format string specifiers in the QUOTE command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNX RTP | =6.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1682 has a severity rating that can lead to potential privilege escalation for remote authenticated users.
To mitigate CVE-2004-1682, it is recommended to upgrade to a patched version of the QNX RTP software.
Only remote authenticated users of QNX 6.1 FTP client are affected by CVE-2004-1682.
CVE-2004-1682 affects systems running QNX RTP version 6.1.
The attack vector for CVE-2004-1682 involves the use of format string specifiers in the QUOTE command within the FTP client.