vendor:
IRIX
by:
LAST STAGE OF DELIRIUM
7.5
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: IRIX
Affected Version From: IRIX 6.2
Affected Version To: IRIX 6.3
Patch Exists: YES
Related CWE: N/A
CPE: o:sgi:irix:6.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
1998
Buffer Overflow in IRIX lpstat
Certain versions of IRIX ship with a version of lpstat which is vulnerable to a buffer overflow attack. The program, lpstat, is used to check the status of the printer being used by the IRIX machine. The problem is in the command line parsing section of the code whereby a user can supply an overly long string and overflow the buffer resulting in a possible root compromise.
Mitigation:
Upgrade to the latest version of IRIX lpstat