SGI NetVisualyzer Arbitrary File Write Vulnerability
BID:5092
Info
SGI NetVisualyzer Arbitrary File Write Vulnerability
| Bugtraq ID: | 5092 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 24 2002 12:00AM |
| Updated: | Jun 24 2002 12:00AM |
| Credit: | Published in SGI advisory 20020607-01-I with thanks given to Walter Roberson. |
| Vulnerable: |
SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: | |
Discussion
SGI NetVisualyzer Arbitrary File Write Vulnerability
A vulnerability has been reported in NetVisualyzer Data Station Software for IRIX. It may be possible for a local attacker to exploit the nveventd binary in order to write data to arbitrary system files. nveventd is installed suid root by default.
A vulnerability has been reported in NetVisualyzer Data Station Software for IRIX. It may be possible for a local attacker to exploit the nveventd binary in order to write data to arbitrary system files. nveventd is installed suid root by default.
Exploit / POC
SGI NetVisualyzer Arbitrary File Write Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
SGI NetVisualyzer Arbitrary File Write Vulnerability
References:
References: