PT-2002-1686 · Sgi · Xfsmd+1
Publicado
2002-07-01
·
Atualizado
2016-10-18
·
CVE-2002-0652
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
xfsmd for IRIX versions 6.5 through 6.5.16
Description
The issue allows remote attackers to execute arbitrary code via shell metacharacters that are not properly filtered from several calls to the popen() function, such as export fs().
Recommendations
For xfsmd for IRIX versions 6.5 through 6.5.16, consider restricting access to the export fs() function until a patch is available. As a temporary workaround, avoid using shell metacharacters in the affected function calls to minimize the risk of exploitation.
Exploit
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Irix
Xfsmd