Vulnerabilities > CVE-2004-1683 - Local Command Execution vulnerability in QNX CRTTrap Path Environment Variable

047910
CVSS 3.7 - LOW
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
local
high complexity
qnx

Summary

A race condition in crrtrap for QNX RTP 6.1 allows local users to gain privileges by modifying the PATH environment variable to reference a malicious io-graphics program before is executed by crrtrap.

Vulnerable Configurations

Part Description Count
Application
Qnx
2