search menu icon-carat-right cmu-wordmark

CERT Coordination Center

QNX PPPoEd vulnerable to buffer overflow

Vulnerability Note VU#961686

Original Release Date: 2005-02-01 | Last Revised: 2005-02-03

Overview

QNX PPPoEd contains a buffer overflow that may allow an attacker to execute arbitrary commands.

Description

QNX is an RTOS (Real-time Operating System). QNX is used in many different devices and industries, including, but not limited to

    • routers
    • manufacturing and processing
    • medical equipment
    • automotive and transportation
    • military and aerospace
    • consumer electronics
    • industry automation and control

The pppoed command is used to start the PPPoEd daemon which provides Point-to-Point Protocol over Ethernet (PPPoE) connections on QNX systems. The syntax of the PPPoEd command is

pppoed [options] [suboptions]

where [options] are user-supplied command-line parameters. A lack of bounds checking on the user-supplied options may allow a buffer overflow to occur. According to some reports, the following command-line options contain this vulnerability:
    • name
    • en
    • upscript
    • downscript
    • retries
    • timeout
    • scriptdetach
    • noscript
    • nodetach
    • remote_mac
    • local_mac

However, other options may also contain this vulnerability,

Impact

An attacker may be able to execute arbitrary commands with elevated privileges or cause a denial-of-service condition.

Solution

We are currently unaware of a practical solution to this problem.

Limit Access to PPPoEd


Deny untrusted users the privileges needed to access the PPPoEd service.

Vendor Information

961686
 

QNX Affected

Updated:  September 10, 2004

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

The vendor has not provided us with any further information regarding this vulnerability.

Addendum

The CERT/CC has no additional comments at this time.

If you have feedback, comments, or additional information about this vulnerability, please send us email.


CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was publicly reported by Julio Cesar Fort.

This document was written by Jeff Gennari.

Other Information

CVE IDs: None
Severity Metric: 10.94
Date Public: 2004-09-05
Date First Published: 2005-02-01
Date Last Updated: 2005-02-03 16:54 UTC
Document Revision: 152

Sponsored by CISA.