vendor:
Irix 6.2
by:
DCRH
7.2
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: Irix 6.2
Affected Version From: Irix 6.2
Affected Version To: Irix 6.2
Patch Exists: YES
Related CWE: N/A
CPE: o:sgi:irix:6.2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: R8000 Power Challenge
1997
Eject Program Vulnerability in Irix 6.2
A vulnerability exists in the eject program shipped with Irix 6.2 from Silicon Graphics. By supplying a long argument to the eject program, it is possible to overwrite the return address on the stack, and execute arbitrary code as root. Eject is normally used to eject removeable media from the system, and as such is setuid root to allow for any user at the console to perform eject operations.
Mitigation:
Upgrade to Irix 6.3 or later.