First published: Mon Sep 13 2004(Updated: )
A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
QNX RTOS | =6.2.0 | |
QNX RTOS | =6.2.0a | |
QNX RTOS | =6.2.0 | |
QNX RTOS | =6.2.0a |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-1683 is considered a high severity vulnerability due to the risk of privilege escalation.
To mitigate CVE-2004-1683, ensure that the PATH environment variable is secure and does not point to any untrusted locations before executing crrtrap.
CVE-2004-1683 affects users of QNX RTP version 6.1 and earlier versions of QNX RTOS such as 6.2.0 and 6.2.0a.
Using QNX RTP 6.1 is risky due to CVE-2004-1683, and it is recommended to upgrade to a patched version.
Local users of QNX RTP 6.1 can exploit CVE-2004-1683 to gain unauthorized privileges.