CVE-2011-4060

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
18/10/2011
Last modified:
11/04/2025

Description

The runtime linker in QNX Neutrino RTOS 6.5.0 before Service Pack 1 does not properly clear the LD_DEBUG_OUTPUT and LD_DEBUG environment variables when a program is spawned from a setuid program, which allows local users to overwrite files via a symlink attack.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:qnx:neutrino_rtos:6.5.0:*:*:*:*:*:*:*