First published: Tue Nov 14 2017(Updated: )
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout of higher privileged processes by manipulating environment variables that influence the loader.
Credit: secure@blackberry.com
Affected Software | Affected Version | How to fix |
---|---|---|
BlackBerry QNX Software Development Platform | =6.5.0 | |
BlackBerry QNX Software Development Platform | =6.5.0-sp1 | |
BlackBerry QNX Software Development Platform | =6.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-9369 is an information disclosure vulnerability in BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier.
The severity of CVE-2017-9369 is medium with a CVSS score of 4.9.
CVE-2017-9369 allows an attacker to gain information about the memory layout of higher privileged processes in the default configuration of BlackBerry QNX SDP.
To fix CVE-2017-9369, update BlackBerry QNX SDP to version 6.6.0 or 6.5.0 SP1 or later.
You can find more information about CVE-2017-9369 at the following link: http://support.blackberry.com/kb/articleDetail?articleNumber=000046674