PT-1994-1008 · Sgi · Irix

Published

1994-10-02

·

Updated

2017-12-19

·

CVE-1999-1022

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IRIX versions 4.x through 5.x
Description The issue concerns the serial ports administrative program, which relies on the user's PATH environmental variable to locate and execute the ls program. This trust in the PATH variable allows local users to potentially gain root privileges by using a Trojan horse ls program.
Recommendations For IRIX versions 4.x through 5.x, consider modifying the serial ports administrative program to use an absolute path for executing the ls program, rather than relying on the user's PATH environmental variable, until a proper fix is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1022

Affected Products

Irix