CVE-2017-3893
low
CVSS v3
1.9
CVSS v2
6.4
VIR risk
1.9
Description
In BlackBerry QNX Software Development Platform (SDP) 6.6.0, the default configuration of the QNX SDP system did not in all circumstances prevent attackers from modifying the GOT or PLT tables with buffer overflow attacks.
Predictions
Exploit likelihood
22%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: secure@blackberry.com — http://support.blackberry.com/kb/articleDetail?articleNumber=000046674
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| blackberry | qnx_software_development_platform | 6.6.0 | |
References
CWEs
CWE-693 CWE-119
Verify integrity in audit chain (admin only). AS-IS.