PT-1997-1186 · Sgi · Sgi Irix
Published
1997-01-04
·
Updated
2017-10-10
·
CVE-1999-1120
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SGI IRIX versions 6.4 and earlier
Description
The issue is related to the netprint feature in SGI IRIX, which trusts the PATH environmental variable to find and execute the disable program. This trust allows local users to gain privileges.
Recommendations
For SGI IRIX versions 6.4 and earlier, consider restricting access to the netprint feature and the disable program to minimize the risk of exploitation. As a temporary workaround, avoid using the netprint feature until a fix is available. At the moment, there is no information about a newer version that contains a fix for this issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sgi Irix