SGI ArrayD ARShell Remote Privilege Escalation Vulnerability
BID:14218
Info
SGI ArrayD ARShell Remote Privilege Escalation Vulnerability
| Bugtraq ID: | 14218 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-1859 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 12 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | This vulnerability was disclosed by the vendor. |
| Vulnerable: |
SGI ProPack 4.0 SGI ProPack 3.0 SP6 SGI ProPack 3.0 SP5 |
| Not Vulnerable: |
SGI ProPack 3.0 SP4 SGI ProPack 3.0 SP3 SGI ProPack 3.0 SP2 SGI ProPack 3.0 SP1 SGI ProPack 3.0 |
Discussion
SGI ArrayD ARShell Remote Privilege Escalation Vulnerability
SGI arshell is susceptible to a remote unspecified privilege escalation vulnerability.
In certain unspecified circumstances, users executing arshell may be able to execute commands on remote array computers with superuser privileges.
This vulnerability allows attackers to gain superuser privileges on any computer in an array or cluster.
Further details are not currently available. This BID will be updated as more information is disclosed.
SGI arshell is susceptible to a remote unspecified privilege escalation vulnerability.
In certain unspecified circumstances, users executing arshell may be able to execute commands on remote array computers with superuser privileges.
This vulnerability allows attackers to gain superuser privileges on any computer in an array or cluster.
Further details are not currently available. This BID will be updated as more information is disclosed.
Exploit / POC
SGI ArrayD ARShell Remote Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SGI ArrayD ARShell Remote Privilege Escalation Vulnerability
Solution:
SGI has released an advisory, along with patches to address this issue.
For users of SGI ProPack 3 Service Pack 5, apply patch 10181.
For users of SGI ProPack 3 Service Pack 6, apply aatch 10185.
For users of SGI ProPack 4, apply patch 10182.
Patches may be obtained from http://support.sgi.com/.
Solution:
SGI has released an advisory, along with patches to address this issue.
For users of SGI ProPack 3 Service Pack 5, apply patch 10181.
For users of SGI ProPack 3 Service Pack 6, apply aatch 10185.
For users of SGI ProPack 4, apply patch 10182.
Patches may be obtained from http://support.sgi.com/.
References
SGI ArrayD ARShell Remote Privilege Escalation Vulnerability
References:
References:
- SGI ProPack for Linux (SGI)