IRIX serial_ports Vulnerability
BID:464
Info
IRIX serial_ports Vulnerability
| Bugtraq ID: | 464 |
| Class: | Race Condition Error |
| CVE: |
CVE-1999-1022 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 02 1994 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was first discovered by transit <[email protected]>, and reported to the no-more-secrets mailing list, on February 2, 1994. It was posted to the Bugtraq mailing list by Tim Newsham <[email protected]> on October 2, 1994. |
| Vulnerable: |
SGI IRIX 5.3 SGI IRIX 5.2 |
| Not Vulnerable: | |
Discussion
IRIX serial_ports Vulnerability
A race condition exists in the serial_ports administrative program, as included by SGI in the 5.x Irix operating system. This race condition allows regular users to execute arbitrary commands as root.
A race condition exists in the serial_ports administrative program, as included by SGI in the 5.x Irix operating system. This race condition allows regular users to execute arbitrary commands as root.
Solution / Fix
IRIX serial_ports Vulnerability
Solution:
Remove the setuid bit from the serial_portsd program:
chmod -s /usr/lib/vadmin/serial_ports.
Patches for this, and other SGI vulnerabilities, can be obtained at http://support.sgi.com.
Solution:
Remove the setuid bit from the serial_portsd program:
chmod -s /usr/lib/vadmin/serial_ports.
Patches for this, and other SGI vulnerabilities, can be obtained at http://support.sgi.com.