PT-1996-1068 · Sgi · Sgi System Tour Package
Publicado
1996-10-30
·
Atualizado
2016-10-18
·
CVE-1999-1384
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SGI system tour package (systour) versions 5.x through 6.3
Description
The issue allows local users to gain root privileges via a Trojan horse .exitops program. This program is called by the inst command, which is executed by the RemoveSystemTour program.
Recommendations
For SGI system tour package (systour) versions 5.x through 6.3, consider removing or restricting access to the .exitops program to prevent exploitation until a fix is available.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sgi System Tour Package