[] NeoSense

QNX RTOS 4.25 - 'CRTTrap' File Disclosure

Author: Simon Ouellette
type: local
platform: linux
port: 
date_added: 2002-05-31 
date_updated: 2012-09-23 
verified: 1 
codes: CVE-2002-0793;OSVDB-12217 
tags: 
aliases:  
screenshot_url:  
application_url: 

source: https://www.securityfocus.com/bid/4901/info

The QNX RTOS crttrap binary includes a command-line option for specifying a configuration file. crttrap is installed setuid by default. crttrap Local attackers may specify an arbitrary system file in place of the configuration file and crttrap will disclose the contents of the arbitrary file.

crttrap -c /etc/shadow