CVE-2006-0623: High severity qnx rtos vulnerability
Published Feb 9, 2006
·Updated
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the file and execute arbitrary code at system startup.
Affected Software
1 affected component
QNX RTOS=6.3.0
Event History
Feb 9, 2006
CVE Published
02:02 AM
CVE Published
via MITRE·07:00 AM
Data Sourced
via MITRE·07:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2006-0623?
CVE-2006-0623 is considered a high severity vulnerability due to its potential for local users to execute arbitrary code.
2
How do I fix CVE-2006-0623?
To fix CVE-2006-0623, change the permissions of /etc/rc.d/rc.local to remove world-writable access.
3
Who is affected by CVE-2006-0623?
CVE-2006-0623 affects systems running QNX Neutrino RTOS version 6.3.0.
4
What can attackers do with CVE-2006-0623?
Attackers can modify /etc/rc.d/rc.local to execute arbitrary commands at system startup.
5
Is CVE-2006-0623 a remote or local vulnerability?
CVE-2006-0623 is a local vulnerability, meaning it can only be exploited by users with local access to the system.