CVE Vulnerabilities

CVE-2004-1391

Published: Dec 31, 2004 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.

Affected Software

NameVendorStart VersionEnd Version
RtosQnx6.1.0 (including)6.1.0 (including)
RtosQnx6.1.0a (including)6.1.0a (including)
RtosQnx6.2.0 (including)6.2.0 (including)
RtosQnx6.2.1a (including)6.2.1a (including)
RtosQnx6.2.1b (including)6.2.1b (including)
RtosQnx6.3.0 (including)6.3.0 (including)
RtpQnx6.1 (including)6.1 (including)

References