IRIX searchbook Vulnerability
BID:463
Info
IRIX searchbook Vulnerability
| Bugtraq ID: | 463 |
| Class: | Access Validation Error |
| CVE: |
CVE-1999-1401 |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 05 1996 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was first reported on December 5, 1996 in a Silicon Graphics security advisory. |
| Vulnerable: |
SGI IRIX 6.2 SGI IRIX 6.1 SGI IRIX 6.0.1 XFS SGI IRIX 6.0.1 SGI IRIX 6.0 SGI IRIX 5.3 XFS SGI IRIX 5.3 SGI IRIX 5.2 SGI IRIX 5.1.1 SGI IRIX 5.1 SGI IRIX 5.0.1 SGI IRIX 5.0 |
| Not Vulnerable: |
SGI IRIX 6.5.4 SGI IRIX 6.5.3 m SGI IRIX 6.5.3 f SGI IRIX 6.5.3 SGI IRIX 6.5.2 m SGI IRIX 6.5.1 SGI IRIX 6.5 SGI IRIX 6.4 SGI IRIX 6.3 |
Discussion
IRIX searchbook Vulnerability
A vulnerability has been discovered in the searchbook application. This application is included with Silicon Graphic's Irix operating system, versions 5.x and 6.x. The searchbook application is used to find local and remote desktop icons. However, it creates files with incorrect permissions that can result in a major security problem.
<home dir>/.desktop-<hostname>/iconbook and
<home dir>/.desktop-<hostname>/searchbook
are created with mode 666. Presumably, searchbook will follow symbolic links, and can be used to create things such as .rhosts files.
A vulnerability has been discovered in the searchbook application. This application is included with Silicon Graphic's Irix operating system, versions 5.x and 6.x. The searchbook application is used to find local and remote desktop icons. However, it creates files with incorrect permissions that can result in a major security problem.
<home dir>/.desktop-<hostname>/iconbook and
<home dir>/.desktop-<hostname>/searchbook
are created with mode 666. Presumably, searchbook will follow symbolic links, and can be used to create things such as .rhosts files.
Exploit / POC
IRIX searchbook Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IRIX searchbook Vulnerability
Solution:
Patches are available for this vulnerability at http//support.sgi.com. The following are the relevant patch numbers:
IRIX 5.2: 1595
IRIX 5.3: 1596
IRIX 6.0.x: None. Users of 6.0.x should upgrade to at least 6.1
IRIX 6.1: 1597
IRIX 6.2: 1598
Solution:
Patches are available for this vulnerability at http//support.sgi.com. The following are the relevant patch numbers:
IRIX 5.2: 1595
IRIX 5.3: 1596
IRIX 6.0.x: None. Users of 6.0.x should upgrade to at least 6.1
IRIX 6.1: 1597
IRIX 6.2: 1598