CVE-1999-0960: High severity SGI IRIX vulnerability
Published Mar 20, 1998
·Updated
IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.
Affected Software
7 affected components
SGI IRIX=5
SGI IRIX=6.0
SGI IRIX=6.0.1
SGI IRIX=6.1
SGI IRIX=6.2
SGI IRIX=6.3
SGI IRIX=6.4
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
sgi/irix/cdplayerfrom your environment.Uninstall or remove the cdplayer utility from affected IRIX systems if it is not required.
- Compensating control
Prevent untrusted local users from invoking cdplayer by restricting access to the binary (use filesystem permissions or ACLs to limit execution to administrative/trusted accounts) and limit which local accounts can log in to hosts running IRIX.
Event History
Mar 20, 1998
CVE Published
05:00 AM
Data Sourced
via NVD·05:00 AM
DescriptionSeverityAffected Software
Jan 4, 2000
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description