IRIX sgihelp Vulnerability
BID:468
Info
IRIX sgihelp Vulnerability
| Bugtraq ID: | 468 |
| Class: | Environment Error |
| CVE: |
CVE-1999-1219 |
| Remote: | No |
| Local: | No |
| Published: | Dec 02 1996 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was first made public in an AUSCERT advisory, dated August 10, 1994. |
| Vulnerable: |
SGI IRIX 5.2 SGI IRIX 5.1 |
| Not Vulnerable: | |
Discussion
IRIX sgihelp Vulnerability
The sgihelp program, from SGI and included with IRIX 5.1 and 5.2, contains a vulnerability. sgihelp contains an option that allows a user to print to a command. Certain SGI utilities, including PrintStatus, printers, scanners, and a number of others, will call this program without changing their uid to the users, from roots. As such, arbitrary commands can be executed as root using the 'print to command' option of sgihelp.
The sgihelp program, from SGI and included with IRIX 5.1 and 5.2, contains a vulnerability. sgihelp contains an option that allows a user to print to a command. Certain SGI utilities, including PrintStatus, printers, scanners, and a number of others, will call this program without changing their uid to the users, from roots. As such, arbitrary commands can be executed as root using the 'print to command' option of sgihelp.
Exploit / POC
IRIX sgihelp Vulnerability
Run PrintStatus
Press the 'help' button.
Select the 'print to command' option. This will allow you to execute anything as root.
Run PrintStatus
Press the 'help' button.
Select the 'print to command' option. This will allow you to execute anything as root.