IRIX runpriv Vulnerability
BID:462
Info
IRIX runpriv Vulnerability
| Bugtraq ID: | 462 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 14 1997 12:00AM |
| Updated: | May 14 1997 12:00AM |
| Credit: | This vulnerability was first made public in an SGI Security Advisory on May 14, 1997. The advisory creditted Joe Bester and Quay Ly of Harvey Mudd College as alerting SGI to this problem. |
| Vulnerable: |
SGI IRIX 6.4 SGI IRIX 6.3 |
| Not Vulnerable: | |
Discussion
IRIX runpriv Vulnerability
A vulnerability exists in the 'runpriv' program, as included with the Irix version 6.3 and 6.4 operating systems. Runpriv is part of the Indigo Magic Administrative Subsystem, part of the System Desktop package, and is intended to be used to allow unpriviledged users to run certain commands as root. SGI reports that a vulnerability in this program may allow any user to execute commands as root. It does require access to the machine in order to exploit the vulnerability.
A vulnerability exists in the 'runpriv' program, as included with the Irix version 6.3 and 6.4 operating systems. Runpriv is part of the Indigo Magic Administrative Subsystem, part of the System Desktop package, and is intended to be used to allow unpriviledged users to run certain commands as root. SGI reports that a vulnerability in this program may allow any user to execute commands as root. It does require access to the machine in order to exploit the vulnerability.
Exploit / POC
IRIX runpriv Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IRIX runpriv Vulnerability
Solution:
A suitable short term solution is to remove teh setuid bit from the runpriv program: chmod -s /usr/sysadm/bin/runpriv
Patches are available for this, and other Irix vulnerabilities, at http://support.sgi.com. The appropriate patch numbers are:
IRIX 6.3 .... patch number 2077
IRIX 6.4 .... patch number 2078
Solution:
A suitable short term solution is to remove teh setuid bit from the runpriv program: chmod -s /usr/sysadm/bin/runpriv
Patches are available for this, and other Irix vulnerabilities, at http://support.sgi.com. The appropriate patch numbers are:
IRIX 6.3 .... patch number 2077
IRIX 6.4 .... patch number 2078