IRIX pset Vulnerability
BID:457
Info
IRIX pset Vulnerability
| Bugtraq ID: | 457 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 17 1997 12:00AM |
| Updated: | Jul 17 1997 12:00AM |
| Credit: | This vulnerability was first reported via an AUSCERT advisory. An exploit was written by the 'Last Stage of Delirium" group in December, 1996. |
| Vulnerable: |
SGI IRIX 6.3 SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 XFS SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 |
| Not Vulnerable: |
SGI IRIX 6.4 |
Discussion
IRIX pset Vulnerability
The pset utility, as shipped by SGI with Irix 5.x and 6.x through 6.3, contains a buffer overflow, which can allow any user on the system to execute arbitrary code on the machine as root. Pset is used to configure and administer processor groups in multiprocessor systems. By supplying a well crafted, long buffer as an argument, the return address on the stack is overwritten, allowing an attacker to execute code other than that which was intended.
The pset utility, as shipped by SGI with Irix 5.x and 6.x through 6.3, contains a buffer overflow, which can allow any user on the system to execute arbitrary code on the machine as root. Pset is used to configure and administer processor groups in multiprocessor systems. By supplying a well crafted, long buffer as an argument, the return address on the stack is overwritten, allowing an attacker to execute code other than that which was intended.
Exploit / POC
Solution / Fix
IRIX pset Vulnerability
Solution:
Patches are available from SGI for this and other vulnerabilities at http://support.sgi.com
Solution:
Patches are available from SGI for this and other vulnerabilities at http://support.sgi.com