CVE-2002-0793
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or…
Does this matter?
Lower severity and a low EPSS score (1.34%). Track it; it rarely justifies an emergency change on its own.
Description
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrite arbitrary files via (1) the -f argument to the monitor utility, (2) the -d argument to dumper, (3) the -c argument to crttrap, or (4) using the Watcom sample utility.
- CVSS 3.1
- 5.5 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-59
- Affected
- blackberry/qnx neutrino real-time operating system
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0292.htmlBroken Link, Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/9231.phpBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4901Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/4902Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/4903Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/4904Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9232Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9233Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9234Third Party Advisory, VDB Entry
- http://archives.neohapsis.com/archives/bugtraq/2002-05/0292.htmlBroken Link, Exploit, Vendor Advisory
- http://www.iss.net/security_center/static/9231.phpBroken Link, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/4901Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/4902Broken Link, Exploit, Patch, Third Party Advisory, VDB Entry, Vendor Advisory
- http://www.securityfocus.com/bid/4903Broken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/4904Broken Link, Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9232Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9233Third Party Advisory, VDB Entry
- https://exchange.xforce.ibmcloud.com/vulnerabilities/9234Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.