vendor:
IRIX
by:
SecurityFocus
7.2
CVSS
HIGH
Information Disclosure
200
CWE
Product Name: IRIX
Affected Version From: SGI IRIX 6.5.22
Affected Version To: SGI IRIX 6.5.22
Patch Exists: No
Related CWE: CVE-2004-0753
CPE: o:sgi:irix
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2004
gr_osview Information Disclosure Vulnerability
gr_osview is prone to an information disclosure vulnerability, which can be exploited by a local attacker to obtain sensitive information such as exposing an administrator's password hash. This issue has been confirmed in SGI IRIX 6.5.22 maintenance release, and other versions of IRIX may be vulnerable as well. The attacker can exploit this vulnerability by running the command 'gr_osview -d -D /etc/shadow'.
Mitigation:
No known mitigation or remediation for this vulnerability.