Phase:Format string vulnerability in fontsleuth in QNX Neutrino RTOS 6.3.0 allows local users to execute arbitrary code via format string specifiers in the zeroth argument (program name).
ReferencesIDEFENSE:Tuesday, February 07, 2006 QNX Neutrino RTOS fontsleuth Command Format String Vulnerability | URL:http://www.idefense.com/intelligence/vulnerabilities/display.php?id=380 | BID:16539 | URL:http://www.securityfocus.com/bid/16539 | FRSIRT:ADV-2006-047
Votes:Assigned (Thursday, February 09, 2006)
Comments:None (candidate not yet proposed)
F7: