PT-1994-1008 · Sgi · Irix
Published
1994-10-02
·
Updated
2017-12-19
·
CVE-1999-1022
CVSS v2.0
6.2
Medium
| Vector | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
IRIX versions 4.x through 5.x
Description
The issue concerns the serial ports administrative program, which relies on the user's PATH environmental variable to locate and execute the ls program. This trust in the PATH variable allows local users to potentially gain root privileges by using a Trojan horse ls program.
Recommendations
For IRIX versions 4.x through 5.x, consider modifying the serial ports administrative program to use an absolute path for executing the ls program, rather than relying on the user's PATH environmental variable, until a proper fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Irix