Vulnerabilities > CVE-2006-0620 - Local Privilege Escalation and Denial Of Service vulnerability in QNX Rtos 6.2.1/6.2.1A/6.2.1B

047910
CVSS 6.2 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
high complexity
qnx
exploit available

Summary

Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows local users to execute arbitrary code via unspecified manipulations of the PHFONT and PHOTON2_PATH environment variables.

Vulnerable Configurations

Part Description Count
Application
Qnx
3

Exploit-Db

descriptionQNX Neutrino 6.2.1 (phfont) Race Condition Local Root Exploit. CVE-2006-0620. Local exploit for qnx platform
idEDB-ID:1479
last seen2016-01-31
modified2006-02-08
published2006-02-08
reporterkokanin
sourcehttps://www.exploit-db.com/download/1479/
titleQNX Neutrino 6.2.1 phfont Race Condition Local Root Exploit