PT-1997-1246 · Sgi · Irix

Publicado

1997-05-07

·

Atualizado

2016-10-18

·

CVE-1999-1461

CVSS v2.0

7.2

Alta

VetorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IRIX versions 5.3 through 6.5.10
Description The issue concerns the inpview in InPerson, which trusts the PATH environmental variable to find and execute the ttsession program. This trust allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.
Recommendations For IRIX versions 5.3 through 6.5.10, consider restricting access to the PATH environmental variable to prevent modification, or implement a secure method to validate the location of the ttsession program before execution. As a temporary workaround, consider setting a fixed path for the ttsession program to prevent exploitation.

Exploit

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-1999-1461

Produtos afetados

Irix