Vulnerabilities > CVE-2005-2725 - Local Arbitrary File Disclosure vulnerability in QNX RTOS InputTrap

047910
CVSS 2.1 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
local
low complexity
qnx
exploit available

Summary

The inputtrap utility in QNX RTOS 6.1.0, 6.3, and possibly earlier versions does not properly check permissions when the -t flag is specified, which allows local users to read arbitrary files.

Vulnerable Configurations

Part Description Count
Application
Qnx
2

Exploit-Db

descriptionQNX RTOS 6.1/6.3 InputTrap Local Arbitrary File Disclosure Vulnerability. CVE-2005-2725. Local exploit for linux platform
idEDB-ID:26195
last seen2016-02-03
modified2005-08-24
published2005-08-24
reporterJulio Cesar Fort
sourcehttps://www.exploit-db.com/download/26195/
titleQNX RTOS 6.1/6.3 InputTrap Local Arbitrary File Disclosure Vulnerability