PT-1996-1068 · Sgi · Sgi System Tour Package
Published
1996-10-30
·
Updated
2016-10-18
·
CVE-1999-1384
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SGI system tour package (systour) versions 5.x through 6.3
Description
The issue allows local users to gain root privileges via a Trojan horse .exitops program. This program is called by the inst command, which is executed by the RemoveSystemTour program.
Recommendations
For SGI system tour package (systour) versions 5.x through 6.3, consider removing or restricting access to the .exitops program to prevent exploitation until a fix is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sgi System Tour Package