CVE-2005-1528: High severity qnx rtos vulnerability
Published Dec 31, 2005
·Updated
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitrary libraries via a LDLIBRARYPATH environment variable that references a malicious library.
Affected Software
1 affected component
QNX RTOS=6.2.1
Event History
Dec 31, 2005
CVE Published
05:00 AM
Feb 9, 2006
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-1528?
CVE-2005-1528 is considered a moderate severity vulnerability due to its ability to allow local users to load arbitrary libraries.
2
How do I fix CVE-2005-1528?
To fix CVE-2005-1528, ensure that the LD_LIBRARY_PATH environment variable is set securely and restrict access to the crttrap command.
3
Who is affected by CVE-2005-1528?
CVE-2005-1528 affects local users of QNX Neutrino RTOS version 6.2.1.
4
What type of vulnerability is CVE-2005-1528?
CVE-2005-1528 is an untrusted search path vulnerability that can lead to arbitrary library loading.
5
Can CVE-2005-1528 be exploited remotely?
CVE-2005-1528 cannot be exploited remotely as it involves local user actions.