PT-1994-1008 · Sgi · Irix

Publicado

1994-10-02

·

Atualizado

2017-12-19

·

CVE-1999-1022

CVSS v2.0

6.2

Média

VetorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IRIX versions 4.x through 5.x
Description The issue concerns the serial ports administrative program, which relies on the user's PATH environmental variable to locate and execute the ls program. This trust in the PATH variable allows local users to potentially gain root privileges by using a Trojan horse ls program.
Recommendations For IRIX versions 4.x through 5.x, consider modifying the serial ports administrative program to use an absolute path for executing the ls program, rather than relying on the user's PATH environmental variable, until a proper fix is available.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1022

Produtos afetados

Irix