PT-2005-1524 · Sgi · Irix
Published
2005-04-08
·
Updated
2008-09-05
·
CVE-2005-0464
CVSS v2.0
2.1
Low
| Vector | AV:L/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
SGI IRIX versions 6.5.22 and possibly other 6.5 versions
Description
The issue concerns a problem where
gr osview in debug mode does not properly drop privileges when opening description files. This allows local users to read a line from arbitrary files by utilizing the -d and -D options, which then prints the line as a formatting error.Recommendations
For SGI IRIX versions 6.5.22 and possibly other 6.5 versions, consider disabling the debug mode for
gr osview until a proper fix is available to prevent exploitation. Restrict access to the gr osview utility to minimize the risk of unauthorized file access.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Irix