PT-1997-1213 · Sgi · Sgi Irix+1
Publicado
1997-05-16
·
Atualizado
2017-12-19
·
CVE-1999-1232
CVSS v2.0
7.2
Alta
| Vetor | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SGI IRIX version 6.2
Description
The issue allows local users to execute arbitrary commands by modifying the PATH environment variable to point to a malicious cp program, exploiting an untrusted search path vulnerability in day5datacopier.
Recommendations
For SGI IRIX version 6.2, consider restricting access to the day5datacopier until a fix is available, and avoid using a modified PATH environment variable that could point to a malicious cp program.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Sgi Irix
Day5Datacopier