IRIX gmemusage Vulnerability
BID:366
Info
IRIX gmemusage Vulnerability
| Bugtraq ID: | 366 |
| Class: | Unknown |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Apr 21 1997 12:00AM |
| Updated: | Apr 21 1997 12:00AM |
| Credit: | This vulnerability was first made public in an SGI security advisory on April 27, 1997. |
| Vulnerable: |
SGI IRIX 6.4 SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 XFS SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 |
| Not Vulnerable: | |
Discussion
IRIX gmemusage Vulnerability
A vulnerability exists in the gmemusage program, as included in Irix 6.x and 5.x from Silicon Graphics Inc. While the details of this vulnerability are not known, SGI recommends taking rapid action to install patches when available, or disabling the program by removing the setuid bit from the program.
A vulnerability exists in the gmemusage program, as included in Irix 6.x and 5.x from Silicon Graphics Inc. While the details of this vulnerability are not known, SGI recommends taking rapid action to install patches when available, or disabling the program by removing the setuid bit from the program.
Solution / Fix
IRIX gmemusage Vulnerability
Solution:
A suitable short term solution is the removal of the setuid bit from the gmemusage program:
chmod -s `find / -name gmemusage -print`
Patches are available from SGI at http://support.sgi.com
Solution:
A suitable short term solution is the removal of the setuid bit from the gmemusage program:
chmod -s `find / -name gmemusage -print`
Patches are available from SGI at http://support.sgi.com