PT-1997-1213 · Sgi · Sgi Irix+1
Published
1997-05-16
·
Updated
2017-12-19
·
CVE-1999-1232
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SGI IRIX version 6.2
Description
The issue allows local users to execute arbitrary commands by modifying the PATH environment variable to point to a malicious cp program, exploiting an untrusted search path vulnerability in day5datacopier.
Recommendations
For SGI IRIX version 6.2, consider restricting access to the day5datacopier until a fix is available, and avoid using a modified PATH environment variable that could point to a malicious cp program.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sgi Irix
Day5Datacopier