SGI IRIX Scheme Login Privilege Escalation Vulnerability
BID:8217
Info
SGI IRIX Scheme Login Privilege Escalation Vulnerability
| Bugtraq ID: | 8217 |
| Class: | Unknown |
| CVE: |
CVE-2003-0574 |
| Remote: | No |
| Local: | Yes |
| Published: | Jul 16 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | This issue was announced by the vendor. |
| Vulnerable: |
SGI IRIX 6.5.20 SGI IRIX 6.5.19 SGI IRIX 6.5.18 SGI IRIX 6.5.17 SGI IRIX 6.5.16 SGI IRIX 6.5.15 SGI IRIX 6.5.14 SGI IRIX 6.5.13 SGI IRIX 6.5.12 SGI IRIX 6.5.11 SGI IRIX 6.5.10 SGI IRIX 6.5.9 SGI IRIX 6.5.8 SGI IRIX 6.5.7 SGI IRIX 6.5.6 SGI IRIX 6.5.5 SGI IRIX 6.5.4 SGI IRIX 6.5.3 SGI IRIX 6.5.2 SGI IRIX 6.5.1 SGI IRIX 6.5 |
| Not Vulnerable: |
SGI IRIX 6.5.21 |
Discussion
SGI IRIX Scheme Login Privilege Escalation Vulnerability
SGI has reported a vulnerability in IRIX that could lead to a local attacker gaining elevated privileges while logging on. The vendor has stated that this condition can occur if certain environment variables are set to particular values, causing /usr/lib/iaf/scheme to dump core. This is likely a buffer overrun vulnerability, though this has not been confirmed by the vendor.
SGI has reported a vulnerability in IRIX that could lead to a local attacker gaining elevated privileges while logging on. The vendor has stated that this condition can occur if certain environment variables are set to particular values, causing /usr/lib/iaf/scheme to dump core. This is likely a buffer overrun vulnerability, though this has not been confirmed by the vendor.
Exploit / POC
SGI IRIX Scheme Login Privilege Escalation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
SGI IRIX Scheme Login Privilege Escalation Vulnerability
Solution:
This issue has been addressed in SGI IRIX 6.5.21. If possible, users are advised to upgrade to this version. The vendor has also released patch 5182 to address the issue for IRIX version 6.5.16 through 6.5.20. Users should contact the vendor for details on obtaining the patch.
Solution:
This issue has been addressed in SGI IRIX 6.5.21. If possible, users are advised to upgrade to this version. The vendor has also released patch 5182 to address the issue for IRIX version 6.5.16 through 6.5.20. Users should contact the vendor for details on obtaining the patch.
References
SGI IRIX Scheme Login Privilege Escalation Vulnerability
References:
References: