First published: Sun Oct 02 1994(Updated: )
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =5.3 | |
SGI IRIX | =5.2 | |
SGI IRIX | =4 | |
=4 | ||
=5.2 | ||
=5.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1022 has a high severity as it allows local users to gain root privileges on affected devices.
To fix CVE-1999-1022, ensure that the PATH environment variable is not misconfigured to include untrusted directories.
CVE-1999-1022 affects SGI IRIX versions 4.x and 5.x, specifically 4 and 5.2 to 5.3.
CVE-1999-1022 is a local privilege escalation vulnerability.
No, CVE-1999-1022 can only be exploited by local users on the affected system.