vendor:
Irix
by:
Unknown
7.5
CVSS
HIGH
Arbitrary Command Execution
78
CWE
Product Name: Irix
Affected Version From: Unknown
Affected Version To: Unknown
Patch Exists: YES
Related CWE: CVE-1999-1170
CPE: o:sgi:irix
Platforms Tested: SGI Irix operating system
Unknown
SGI Irix rmail Utility Arbitrary Command Execution Vulnerability
The rmail utility included in SGI Irix operating system is vulnerable to arbitrary command execution. This vulnerability occurs due to a lack of input validation on the contents of an environment variable. An attacker can exploit this vulnerability to execute arbitrary commands with the gid mail privilege level. The rmail utility is commonly used with uucp.
Mitigation:
Apply the necessary patches provided by SGI. Additionally, restrict the use of the rmail utility and limit access to privileged accounts.