IRIX SpaceWare Vulnerability
BID:471
Info
IRIX SpaceWare Vulnerability
| Bugtraq ID: | 471 |
| Class: | Unknown |
| CVE: |
CVE-1999-1399 |
| Remote: | No |
| Local: | No |
| Published: | Oct 30 1996 12:00AM |
| Updated: | Jul 11 2009 12:56AM |
| Credit: | This vulnerability was found by J.A. Guitierrez <[email protected]>, and reported to the Bugtraq mailing list on August 20, 1997. |
| Vulnerable: |
SGI IRIX 6.2 |
| Not Vulnerable: | |
Discussion
IRIX SpaceWare Vulnerability
The SpaceBall game, shipped with Irix 6.2 from Silicon Graphics contains a security hole which could result in the compromise of the root account. By blindly taking the contents of the $HOSTNAME variable, and not placing quotes around it, the spaceball.sh program can be made to execute commands.
The SpaceBall game, shipped with Irix 6.2 from Silicon Graphics contains a security hole which could result in the compromise of the root account. By blindly taking the contents of the $HOSTNAME variable, and not placing quotes around it, the spaceball.sh program can be made to execute commands.