CVE-1999-0036: Malicious File Upload
IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Set the LOCKOUT parameter to 0 for the IRIX login program to avoid allowing creation or damage to files when LOCKOUT is nonzero.
IRIX login program LOCKOUT = 0
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0036?
The severity of CVE-1999-0036 is considered medium due to its potential for unauthorized file creation or damage.
How do I fix CVE-1999-0036?
To fix CVE-1999-0036, you should ensure that the LOCKOUT parameter is set to zero in the IRIX login program.
Which versions of SGI IRIX are affected by CVE-1999-0036?
CVE-1999-0036 affects SGI IRIX versions 5.1, 5.2, 5.3, 6.0, 6.1, 6.2, 6.3, and 6.4.
What are the potential risks of CVE-1999-0036?
The potential risks of CVE-1999-0036 include unauthorized file modifications and the ability to exploit system security.
Is there a workaround for CVE-1999-0036?
A workaround for CVE-1999-0036 includes disabling or modifying the LOCKOUT parameter in the IRIX login program settings.