CVE-2017-3892: Infoleak
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout that could be used in a blended attack by executing commands targeting procfs resources.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-3892?
CVE-2017-3892 is an information disclosure vulnerability in the default configuration of the BlackBerry QNX Software Development Platform (SDP) 6.6.0.
How severe is CVE-2017-3892?
CVE-2017-3892 has a severity rating of 7.5, which is considered high.
How does CVE-2017-3892 affect BlackBerry QNX Software Development Platform?
CVE-2017-3892 affects BlackBerry QNX Software Development Platform (SDP) 6.6.0 by allowing an attacker to gain information relating to memory layout that could be used in a blended attack.
Is there a fix available for CVE-2017-3892?
Yes, BlackBerry has released a fix for CVE-2017-3892. It is recommended to update to a version of QNX SDP that is not affected by the vulnerability.
Where can I find more information about CVE-2017-3892?
You can find more information about CVE-2017-3892 on the BlackBerry support page: http://support.blackberry.com/kb/articleDetail?articleNumber=000046674