First published: Fri May 16 1997(Updated: )
Untrusted search path vulnerability in day5datacopier in SGI IRIX 6.2 allows local users to execute arbitrary commands via a modified PATH environment variable that points to a malicious cp program.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =6.2 | |
=6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1232 has a medium severity level, as it allows local users to execute arbitrary commands.
To fix CVE-1999-1232, ensure that the PATH environment variable does not include untrusted directories.
Local users of SGI IRIX version 6.2 are affected by CVE-1999-1232.
CVE-1999-1232 is an untrusted search path vulnerability.
CVE-1999-1232 cannot be exploited remotely as it requires local access to the vulnerable system.