vendor:
Irix 6.2
by:
Last Stage of Delirium
7.2
CVSS
HIGH
Buffer Overflow
120
CWE
Product Name: Irix 6.2
Affected Version From: Irix 6.2
Affected Version To: Irix 6.2
Patch Exists: YES
Related CWE: N/A
CPE: o:sgi:irix:6.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
1996
Buffer Overflow in Eject Program
A vulnerability exists in the eject program shipped with Irix 6.2 from Silicon Graphics. By supplying a long argument to the eject program, it is possible to overwrite the return address on the stack, and execute arbitrary code as root. Eject is normally used to eject removeable media from the system, and as such is setuid root to allow for any user at the console to perform eject operations.
Mitigation:
Upgrade to the latest version of Irix 6.2.