IRIX ipxlink Vulnerability
BID:71
Info
IRIX ipxlink Vulnerability
| Bugtraq ID: | 71 |
| Class: | Unknown |
| CVE: |
CVE-1999-1501 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 08 1998 12:00AM |
| Updated: | Jul 11 2009 12:16AM |
| Credit: | This vulnerability was published as "SGI O2 ipx security issue" by Fabrice Planchon <[email protected]> to the BugTraq mailing list on April 8, 1998. |
| Vulnerable: |
SGI IRIX 6.3 |
| Not Vulnerable: | |
Discussion
IRIX ipxlink Vulnerability
SGI O2 systems running IRIX 6.3 come with support
for the IPX protocol. The software is installed by default,
and lives under /usr/etc/netware. The binary ipxlink is
part of this subsystem.
Among many vulnerabilities in this binary it calls other
programs via system() without reseting the enviroment
(e.g. IFS).
This is SGI bug number 498565.
SGI O2 systems running IRIX 6.3 come with support
for the IPX protocol. The software is installed by default,
and lives under /usr/etc/netware. The binary ipxlink is
part of this subsystem.
Among many vulnerabilities in this binary it calls other
programs via system() without reseting the enviroment
(e.g. IFS).
This is SGI bug number 498565.
Exploit / POC
IRIX ipxlink Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution / Fix
IRIX ipxlink Vulnerability
Solution:
Turn of the setuid bit of this binary or apply the SGI Patch
SG0002869. Note that this patch is not available with a
support contract.
Solution:
Turn of the setuid bit of this binary or apply the SGI Patch
SG0002869. Note that this patch is not available with a
support contract.
References
IRIX ipxlink Vulnerability
References:
References: