serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
References
Link | Resource |
---|---|
http://www.securityfocus.com/archive/1/930 | Exploit Vendor Advisory |
http://www.securityfocus.com/bid/464 | Exploit Patch Vendor Advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/2111 |
Configurations
Configuration 1 (hide)
|
Information
Published : 1994-10-01 21:00
Updated : 2017-12-18 18:29
NVD link : CVE-1999-1022
Mitre link : CVE-1999-1022
JSON object : View
CWE
Products Affected
sgi
- irix