Vulnerabilities > CVE-2008-3024 - Out-Of-Bounds Write vulnerability in Blackberry QNX Momentics 6.2.0/6.3.0/6.3.2
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 |
Common Weakness Enumeration (CWE)
Exploit-Db
description | QNX Neutrino RTOS 6.3 'phgrafx' Local Buffer Overflow Vulnerability. CVE-2008-3024. Dos exploit for unix platform |
id | EDB-ID:32009 |
last seen | 2016-02-03 |
modified | 2008-07-01 |
published | 2008-07-01 |
reporter | Filipe Balestra |
source | https://www.exploit-db.com/download/32009/ |
title | QNX Neutrino RTOS 6.3 - 'phgrafx' Local Buffer Overflow Vulnerability |
References
- http://secunia.com/advisories/30808
- http://securityreason.com/securityalert/3974
- http://www.scanit.net/rd/advisories/adv01
- http://www.securityfocus.com/archive/1/493816/100/0/threaded
- http://www.securityfocus.com/bid/30024
- http://www.securitytracker.com/id?1020411
- http://www.vupen.com/english/advisories/2008/1996/references
- https://exchange.xforce.ibmcloud.com/vulnerabilities/43542