Back to Database
Status published
Medium
CVE-2004-1391
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in...
Vulnerability Description
Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2004-1391
Credits & Attribution
No credits recorded in the NVD database.
References
More from qnx
View All →CVE-2011-4060
The runtime linker in QNX Neutrino RTOS 6.5.0 before Service...
Low
3.3
CVE-2006-0623
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which...
High
7.2
CVE-2006-0622
QNX Neutrino RTOS 6.3.0 allows local users to cause a...
Medium
4.9
CVE-2006-0621
Multiple buffer overflows in QNX Neutrino RTOS 6.2.0 allow local...
High
7.2
CVE-2006-0620
Race condition in phfont in QNX Neutrino RTOS 6.2.1 allows...
Medium
6.2
Affected Vendor
Affected Software
rtos, rtp
Vulnerable Versions:
6.1.0, 6.1.0a, 6.2.0, 6.2.1a, 6.2.1b, 6.3.0, 6.1
Timeline
Official Publish:
February 6th, 2005
Last Modified:
August 8th, 2024
Added to House:
July 18th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.