vendor:
IRIX
by:
DCRH
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: IRIX
Affected Version From: 5.x
Affected Version To: 6.x
Patch Exists: YES
Related CWE: N/A
CPE: o:sgi:irix:6.5.22
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2000
Buffer Overflow in IRIX ‘df’ Utility
A buffer overflow exists in IRIX 5.x and 6.x 'df' utility, from Silicon Graphics Inc. By supplying a long argument to the -f option of df, a user can crash the df program. By carefully crafting a buffer containing machine executable code, an attacker can run arbitrary commands as root.
Mitigation:
Upgrade to the latest version of IRIX.