CVE-1999-0313: High severity sgi irix vulnerability
diskbandwidth on SGI IRIX 6.4 S2MP for Origin/Onyx2 allows local users to gain root access using relative pathnames.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Prevent unprivileged local users from executing or accessing the disk_bandwidth utility on affected SGI IRIX 6.4 S2MP (Origin/Onyx2) systems until a vendor-supplied fix is available. Restrict console and SSH access to trusted administrators only, and apply strict local account controls (remove or disable unneeded accounts, enforce least privilege).
- Operational
Treat affected systems as potentially compromised if untrusted local user access occurred: perform incident response (investigate for signs of local privilege escalation and root compromise), restore affected hosts from known-good backups if compromise is found, and rotate any credentials or keys that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-0313?
CVE-1999-0313 is considered a critical vulnerability as it allows local users to gain root access.
How do I fix CVE-1999-0313?
To fix CVE-1999-0313, apply patches provided by SGI or upgrade to a more secure version of IRIX.
Who is affected by CVE-1999-0313?
CVE-1999-0313 affects local users on SGI IRIX 6.4 S2MP systems for Origin/Onyx2 hardware.
What type of vulnerability is CVE-1999-0313?
CVE-1999-0313 is a privilege escalation vulnerability that enables unauthorized root access.
Is CVE-1999-0313 still a concern today?
While CVE-1999-0313 pertains to an older system, it remains a concern for any legacy installations still in use.