Information Disclosure Vulnerability in BlackBerry QNX Software Development Platform
CVE-2017-9369

4.9MEDIUM

Key Information:

Vendor

Blackberry

Vendor
CVE Published:
14 November 2017

What is CVE-2017-9369?

The BlackBerry QNX Software Development Platform (SDP) versions 6.6.0 and 6.5.0 SP1, along with earlier releases, contain an information disclosure vulnerability. This flaw allows attackers to exploit the default configuration to reveal sensitive information regarding the memory layout of more privileged processes. By manipulating specific environment variables that influence the loader, an attacker can gain unauthorized insights into the system's memory structure. It is crucial to address this vulnerability to mitigate the risk of potential data leaks and enhance overall security.

Affected Version(s)

QNX Software Development Platform (QNX SDP) 6.6.0

QNX Software Development Platform (QNX SDP) 6.5.0 SP1 and earlier

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.