CVE-2017-9369: Infoleak
In BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier, an information disclosure vulnerability in the default configuration of the QNX SDP could allow an attacker to gain information relating to memory layout of higher privileged processes by manipulating environment variables that influence the loader.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2017-9369?
CVE-2017-9369 is an information disclosure vulnerability in BlackBerry QNX Software Development Platform (SDP) 6.6.0 and 6.5.0 SP1 and earlier.
What is the severity of CVE-2017-9369?
The severity of CVE-2017-9369 is medium with a CVSS score of 4.9.
How does CVE-2017-9369 affect BlackBerry QNX Software Development Platform?
CVE-2017-9369 allows an attacker to gain information about the memory layout of higher privileged processes in the default configuration of BlackBerry QNX SDP.
What is the fix for CVE-2017-9369?
To fix CVE-2017-9369, update BlackBerry QNX SDP to version 6.6.0 or 6.5.0 SP1 or later.
Where can I find more information about CVE-2017-9369?
You can find more information about CVE-2017-9369 at the following link: http://support.blackberry.com/kb/articleDetail?articleNumber=000046674