Untrusted execution path vulnerability in the PPPoE daemon (PPPoEd) in QNX RTP 6.1 allows local users to execute arbitrary programs by modifying the PATH environment variable to point to a malicious mount program.
| Software | From | Fixed in |
|---|---|---|
| qnx / rtos | 6.2.0 | 6.2.0.x |
| qnx / rtp | 6.1 | 6.1.x |
| qnx / rtos | 6.2.1b | 6.2.1b.x |
| qnx / rtos | 6.3.0 | 6.3.0.x |
| qnx / rtos | 6.1.0a | 6.1.0a.x |
| qnx / rtos | 6.2.1a | 6.2.1a.x |
| qnx / rtos | 6.1.0 | 6.1.0.x |