IRIX csetup Vulnerability

BID:684

Info

IRIX csetup Vulnerability

Bugtraq ID: 684
Class: Access Validation Error
CVE:
Remote: No
Local: Yes
Published: Jan 06 1997 12:00AM
Updated: Jan 06 1997 12:00AM
Credit: This vulnerability was discovered by Yuri Volobuev <[email protected]> and reported to bugtraq on 6 Januari 1997.
Vulnerable: SGI IRIX 6.2
SGI IRIX 6.1
SGI IRIX 6.0.1
SGI IRIX 6.0
SGI IRIX 5.3
SGI IRIX 5.2
SGI IRIX 5.1.1
SGI IRIX 5.1
SGI IRIX 5.0.1
SGI IRIX 5.0
Not Vulnerable: SGI IRIX 6.4
SGI IRIX 6.3

Discussion

IRIX csetup Vulnerability

This is the description about the problem given by Yuri Volobuev who found the problem:

ABSTRACT

/usr/Cadmin/bin/csetup is root/suid and buggy. It has a vulnerability that allows any local user to get root privileges.

FIX

chmod u-s /usr/Cadmin/bin/csetup

Full story.

While I was freezing my ass off in Ames, IA, making frequent trips to video rental store, Jay was doing something less lame and found an interesting thing: if one does setenv DEBUG_CSETUP 1 and then runs csetup, it'll create a file /usr/tmp/csetupLog, owned by root. Sure enough, it follows symlinks, follows umask if file is nonexistant, overwrites existing file keeping original permissions. csetup will display a dialog window on startup, asking for root password. However, one can press Cancel and it will proceed in "read-only" mode. Perhaps it was considered to be enough protection, so it doesn't bother dropping root privileges.

The log file looks like

Remote Host: xxx Address : xxx.xxx.xxx.xxx
Set Initial Timeout (objectserver) : 1
Get Lego objects Info
Finished Loading objects info
Networking Panel initialization complete!

and there's no easy way to alter its contents, thus no easy way to exploit it. Yet another DoS attack, right? Well, so we thought. On an ideal OS, it probably is. But it's Irix. I felt it more than DoS. I didn't try too hard to find it, though, and the other day I was brushing my teeth and it came by itself. Log file contains nice text, not just some binary crap. So from the OS view point it's a shell script. sh will be invoked to execute it, and it'll try to execute command called "Remote". So we can overwrite some system binary and make some program running as root execute it. But
one has to have control over PATH for it to be profitable. That's where Irix helps us. Some may remember an old advisory about sgihelp, it was recommended that people _remove sgihelp_ till patch is installed, pretty amazing, huh? That's because all those GUI tools that run as root invoke sgihelp without bothering to change uid first. Old sgihelp didn't care if uid/euid=0, you can imagine what this means. New one does drop root very early, but it doesn't solve the real problem: many GUI tools calling external program while euid=0, which is totally unnecessary. Sure, it's easier to fix one program than a whole bunch of them, I'm very lazy myself so I can understand, but there's a price. One doesn't need to go far to find an example, csetup itself does it. So, do setenv DEBUG_CSETUP 1, symlink /usr/tmp/casetupLog to /usr/sbin/sgihelp, put infamous makesh called "Remote" first in your PATH, run csetup. At this point sgihelp is nuked. Now click on Help button, and enjoy. Remember to make a copy of real sgihelp first.

Exploit / POC

IRIX csetup Vulnerability

See the Discussion section for a description of an exploit.

Solution / Fix

IRIX csetup Vulnerability

Solution:
Remove the setuid flag from the csetup executable or install the patches supplied by SGI:

**** IRIX 5.0.x, 5.1.x ****

For the IRIX operating systems versions 5.0.x and 5.1.x, an upgrade
to 5.2 or better is required first. When the upgrade is completed,
then the patches described in the following sections can be applied
depending on the final version of the upgrade.

**** IRIX 5.2 ****

##### Checksums ####

The actual patch will be a tar file containing the following files:

Filename: README.patch.1754
Algorithm #1 (sum -r): 02298 9 README.patch.1754
Algorithm #2 (sum): 4311 9 README.patch.1754
MD5 checksum: 91F6B5EF4E28601F6F5B0BA7FCC60F05

Filename: patchSG0001754
Algorithm #1 (sum -r): 36996 2 patchSG0001754
Algorithm #2 (sum): 2278 2 patchSG0001754
MD5 checksum: FE38D83EF39C24E9957174D40778CC84

Filename: patchSG0001754.desktop_eoe_sw
Algorithm #1 (sum -r): 11539 7 patchSG0001754.desktop_eoe_sw
Algorithm #2 (sum): 58449 7 patchSG0001754.desktop_eoe_sw
MD5 checksum: DD891AA74B5A9326FC56451C8E6574BC

Filename: patchSG0001754.idb
Algorithm #1 (sum -r): 10077 11 patchSG0001754.idb
Algorithm #2 (sum): 10878 11 patchSG0001754.idb
MD5 checksum: 26BB76AF0614470363974E165F2AF185

Filename: patchSG0001754.sysadmdesktop_sw
Algorithm #1 (sum -r): 24443 1681 patchSG0001754.sysadmdesktop_sw
Algorithm #2 (sum): 28260 1681 patchSG0001754.sysadmdesktop_sw
MD5 checksum: AEE458C8636787693A3AEA7F999F3811

**** IRIX 5.3 ****

##### Checksums ####

The actual patch will be a tar file containing the following files:

Filename: README.patch.1751
Algorithm #1 (sum -r): 27916 9 README.patch.1751
Algorithm #2 (sum): 19331 9 README.patch.1751
MD5 checksum: 88545535FDFBA1CF13185574BBCE89B2

Filename: patchSG0001751
Algorithm #1 (sum -r): 15185 3 patchSG0001751
Algorithm #2 (sum): 30882 3 patchSG0001751
MD5 checksum: BF09436F9EFFD8656D091072AD0AF7B8

Filename: patchSG0001751.desktop_eoe_sw
Algorithm #1 (sum -r): 61424 108 patchSG0001751.desktop_eoe_sw
Algorithm #2 (sum): 18298 108 patchSG0001751.desktop_eoe_sw
MD5 checksum: B54CFF60CC366E77633729F6F678D89D

Filename: patchSG0001751.idb
Algorithm #1 (sum -r): 64366 12 patchSG0001751.idb
Algorithm #2 (sum): 50303 12 patchSG0001751.idb
MD5 checksum: EA9732CE87EC4CF595AAFB99FCAD626C

Filename: patchSG0001751.sysadmdesktop_sw
Algorithm #1 (sum -r): 25676 2872 patchSG0001751.sysadmdesktop_sw
Algorithm #2 (sum): 47832 2872 patchSG0001751.sysadmdesktop_sw
MD5 checksum: AA56293C87F356F36D242A456519C6A6

**** IRIX 6.1 ****

##### Checksums ####

The actual patch will be a tar file containing the following files:

Filename: README.patch.1752
Algorithm #1 (sum -r): 42942 9 README.patch.1752
Algorithm #2 (sum): 4305 9 README.patch.1752
MD5 checksum: D44673631AF2CB4307D943FE0CE3FA1B

Filename: patchSG0001752
Algorithm #1 (sum -r): 63770 2 patchSG0001752
Algorithm #2 (sum): 6993 2 patchSG0001752
MD5 checksum: 55D100093FB589A700E255096101E552

Filename: patchSG0001752.desktop_eoe_sw
Algorithm #1 (sum -r): 03764 106 patchSG0001752.desktop_eoe_sw
Algorithm #2 (sum): 20836 106 patchSG0001752.desktop_eoe_sw
MD5 checksum: 6E683D20DEEFE9F11E7C70CF798DC05E

Filename: patchSG0001752.idb
Algorithm #1 (sum -r): 44444 11 patchSG0001752.idb
Algorithm #2 (sum): 24120 11 patchSG0001752.idb
MD5 checksum: C3E0E359958309C8BE78C01A1BABF7F2

Filename: patchSG0001752.sysadmdesktop_sw
Algorithm #1 (sum -r): 14096 2848 patchSG0001752.sysadmdesktop_sw
Algorithm #2 (sum): 63751 2848 patchSG0001752.sysadmdesktop_sw
MD5 checksum: 7BBF9EEB3CA09610EF585A2A6E8E567E

**** IRIX 6.2 ****

##### Checksums ####

The actual patch will be a tar file containing the following files:

Filename: README.patch.1753
Algorithm #1 (sum -r): 24454 9 README.patch.1753
Algorithm #2 (sum): 4319 9 README.patch.1753
MD5 checksum: EB0BBC4258E68F10C373B0972AE55394

Filename: patchSG0001753
Algorithm #1 (sum -r): 24051 2 patchSG0001753
Algorithm #2 (sum): 13058 2 patchSG0001753
MD5 checksum: CF8DE7471FAB609DF6AA16A74687F673

Filename: patchSG0001753.desktop_eoe_sw
Algorithm #1 (sum -r): 00728 106 patchSG0001753.desktop_eoe_sw
Algorithm #2 (sum): 59678 106 patchSG0001753.desktop_eoe_sw
MD5 checksum: 0D558206D1C4C767B3B51054AAAD0861

Filename: patchSG0001753.idb
Algorithm #1 (sum -r): 55921 11 patchSG0001753.idb
Algorithm #2 (sum): 24555 11 patchSG0001753.idb
MD5 checksum: 920F31FE9B805D0CE260CE9950F93075

Filename: patchSG0001753.sysadmdesktop_sw
Algorithm #1 (sum -r): 52792 2859 patchSG0001753.sysadmdesktop_sw
Algorithm #2 (sum): 54670 2859 patchSG0001753.sysadmdesktop_sw
MD5 checksum: 78A186F052851EBD7CD3E1408B1548D5

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report