IRIX df Vulnerability
BID:346
Info
IRIX df Vulnerability
| Bugtraq ID: | 346 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 24 1997 12:00AM |
| Updated: | May 24 1997 12:00AM |
| Credit: | This vulnerability was reported to the Bugtraq mailing list by David Hedley ([email protected]) on May 24, 1997. |
| Vulnerable: |
SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 5.3 |
| Not Vulnerable: | |
Discussion
IRIX df Vulnerability
A buffer overflow exists in IRIX 5.x and 6.x 'df' utility, from Silicon Graphics Inc. By supplying a long argument to the -f option of df, a user can crash the df program. By carefully crafting a buffer containing machine executable code, an attacker can run arbitrary commands as root.
A buffer overflow exists in IRIX 5.x and 6.x 'df' utility, from Silicon Graphics Inc. By supplying a long argument to the -f option of df, a user can crash the df program. By carefully crafting a buffer containing machine executable code, an attacker can run arbitrary commands as root.
Solution / Fix
IRIX df Vulnerability
Solution:
Suitable temporary solutions include removing the setuid bit from the binary: chmod -s /bin/df
Patches are available from SGI at http://support.sgi.com.
Solution:
Suitable temporary solutions include removing the setuid bit from the binary: chmod -s /bin/df
Patches are available from SGI at http://support.sgi.com.