CVE-2004-1683: Race Condition
Published Sep 13, 2004
·Updated
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.
Affected Software
4 affected components
QNX RTOS=6.2.0
QNX RTOS=6.2.0a
QNX RTOS=6.2.0
QNX RTOS=6.2.0a
Event History
Sep 13, 2004
CVE Published
04:00 AM
Feb 20, 2005
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1683?
CVE-2004-1683 is considered a high severity vulnerability due to the risk of privilege escalation.
2
How do I fix CVE-2004-1683?
To mitigate CVE-2004-1683, ensure that the PATH environment variable is secure and does not point to any untrusted locations before executing crrtrap.
3
What systems are affected by CVE-2004-1683?
CVE-2004-1683 affects users of QNX RTP version 6.1 and earlier versions of QNX RTOS such as 6.2.0 and 6.2.0a.
4
Can I still use QNX RTP 6.1 if CVE-2004-1683 is present?
Using QNX RTP 6.1 is risky due to CVE-2004-1683, and it is recommended to upgrade to a patched version.
5
Who is vulnerable to CVE-2004-1683?
Local users of QNX RTP 6.1 can exploit CVE-2004-1683 to gain unauthorized privileges.