PT-1997-1246 · Sgi · Irix

Published

1997-05-07

·

Updated

2016-10-18

·

CVE-1999-1461

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions IRIX versions 5.3 through 6.5.10
Description The issue concerns the inpview in InPerson, which trusts the PATH environmental variable to find and execute the ttsession program. This trust allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.
Recommendations For IRIX versions 5.3 through 6.5.10, consider restricting access to the PATH environmental variable to prevent modification, or implement a secure method to validate the location of the ttsession program before execution. As a temporary workaround, consider setting a fixed path for the ttsession program to prevent exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1461

Affected Products

Irix