Vulnerabilities > CVE-1999-1022 - Unspecified vulnerability in SGI Irix 4/5.2/5.3

047910
CVSS 6.2 - MEDIUM
Attack vector
LOCAL
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
high complexity
sgi
exploit available

Summary

serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.

Vulnerable Configurations

Part Description Count
OS
Sgi
3

Exploit-Db

descriptionSGI IRIX 5.2/5.3 serial_ports Vulnerability. CVE-1999-1022. Local exploit for irix platform
idEDB-ID:19351
last seen2016-02-02
modified1994-02-02
published1994-02-02
reportertransit
sourcehttps://www.exploit-db.com/download/19351/
titleSGI IRIX 5.2/5.3 serial_ports Vulnerability