PT-1994-1008 · Sgi · Irix
Publicado
1994-10-02
·
Atualizado
2017-12-19
·
CVE-1999-1022
CVSS v2.0
6.2
Média
| Vetor | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IRIX versions 4.x through 5.x
Description
The issue concerns the serial ports administrative program, which relies on the user's PATH environmental variable to locate and execute the ls program. This trust in the PATH variable allows local users to potentially gain root privileges by using a Trojan horse ls program.
Recommendations
For IRIX versions 4.x through 5.x, consider modifying the serial ports administrative program to use an absolute path for executing the ls program, rather than relying on the user's PATH environmental variable, until a proper fix is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Irix