Photon microGUI in QNX Neutrino realtime operating system (RTOS) 6.1.0 and 6.2.0 allows attackers to read user clipboard information via a direct request to the 1.TEXT file in a directory whose name is a hex-encoded user ID.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.iss.net/security_center/static/10658.php | vdb entry |
http://www.securityfocus.com/bid/6207 | vdb entry |
http://archives.neohapsis.com/archives/bugtraq/2002-11/0267.html | mailing list |