Vulnerabilities > CVE-2008-3024 - Out-Of-Bounds Write vulnerability in Blackberry QNX Momentics 6.2.0/6.3.0/6.3.2

047910
CVSS 9.3 - CRITICAL
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
blackberry
CWE-787
critical
exploit available

Summary

Stack-based buffer overflow in phgrafx in QNX Momentics (aka RTOS) 6.3.2 and earlier allows local users to gain privileges via a long .pal filename in palette/.

Vulnerable Configurations

Part Description Count
Application
Blackberry
3

Common Weakness Enumeration (CWE)

Exploit-Db

descriptionQNX Neutrino RTOS 6.3 'phgrafx' Local Buffer Overflow Vulnerability. CVE-2008-3024. Dos exploit for unix platform
idEDB-ID:32009
last seen2016-02-03
modified2008-07-01
published2008-07-01
reporterFilipe Balestra
sourcehttps://www.exploit-db.com/download/32009/
titleQNX Neutrino RTOS 6.3 - 'phgrafx' Local Buffer Overflow Vulnerability