Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-2687


Stack-based buffer overflow in the bpe_decompress function in (1) BlackBerry QNX Neutrino RTOS through 6.5.0 SP1 and (2) QNX Momentics Tool Suite through 6.5.0 SP1 in the QNX Software Development Platform allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via crafted packets to TCP port 4868.


Published

2013-07-12T16:55:01.037

Last Modified

2025-04-11T00:51:21.963

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 7.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

10.0

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-119

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application blackberry qnx_momentics_tool_suite ≤ 6.5.0 Yes
Application blackberry qnx_momentics_tool_suite 4.5 Yes
Application blackberry qnx_momentics_tool_suite 4.6 Yes
Application blackberry qnx_momentics_tool_suite 4.7 Yes
Application blackberry qnx_momentics_tool_suite 6.5.0 Yes
Application blackberry qnx_software_development_platform - Yes
Operating System blackberry qnx_neutrino_rtos ≤ 6.5.0 Yes
Operating System blackberry qnx_neutrino_rtos 6.4.1 Yes
Operating System blackberry qnx_neutrino_rtos 6.5.0 Yes

References