vendor:
IRIX 6.4 S2MP
by:
Loneguard
7.2
CVSS
HIGH
Local Privilege Escalation
269
CWE
Product Name: IRIX 6.4 S2MP
Affected Version From: IRIX 6.4 S2MP
Affected Version To: IRIX 6.4 S2MP
Patch Exists: NO
Related CWE: N/A
CPE: o:sgi:irix:6.4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Irix 6.4
1997
Irix 6.4 ioconfig xploit
A vulnerability exists in the ioconfig program, as shipping with IRIX 6.4 S2MP from Silicon Graphics, Inc. This program is only available on Irix 6.4 for the Origin/Onyx2. Other machines running IRIX are not vulnerable. This vulnerability will allow a local user to obtain root priveledges. The ioconfig program will make calls to the system() call without setting the path to be used; this allows an attacker to alter their path to cause ioconfig to execute arbitrary programs.
Mitigation:
Ensure that the PATH environment variable is set correctly when calling system().