IRIX ipxchk Vulnerability
BID:70
Info
IRIX ipxchk Vulnerability
| Bugtraq ID: | 70 |
| Class: | Unknown |
| CVE: |
CVE-1999-1501 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was published as "SGI O2 ipx security issue" by Fabrice Planchon <[email protected]> to the BugTraq mailing list on April 8, 1998. |
| Vulnerable: |
SGI IRIX 6.3 |
| Not Vulnerable: | |
Discussion
IRIX ipxchk Vulnerability
SGI O2 systems running IRIX 6.3 come with support
for the IPX protocol. The software is installed by default,
and lives under /usr/etc/netware. The binary ipxchk is
part of this subsystem.
Among many vulnerabilities in this binary it calls other
programs via system() without reseting the enviroment
(e.g. IFS).
This is SGI bug number 498565.
SGI O2 systems running IRIX 6.3 come with support
for the IPX protocol. The software is installed by default,
and lives under /usr/etc/netware. The binary ipxchk is
part of this subsystem.
Among many vulnerabilities in this binary it calls other
programs via system() without reseting the enviroment
(e.g. IFS).
This is SGI bug number 498565.
Exploit / POC
IRIX ipxchk Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IRIX ipxchk Vulnerability
Solution:
Turn of the suid bit on the binary or apply the SGI Patch
SG0002869. Note that this patch is not avaiable without
a support contract.
Solution:
Turn of the suid bit on the binary or apply the SGI Patch
SG0002869. Note that this patch is not avaiable without
a support contract.