CVE-1999-1286: High severity SGI IRIX vulnerability
addnetpr in SGI IRIX 6.2 and earlier allows local users to modify arbitrary files and possibly gain root access via a symlink attack on a temporary file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SGI IRIX addnetprfrom your environment.Uninstall or remove the addnetpr program/binary from systems running SGI IRIX if it is not required.
- Configuration
Change filesystem permissions so only root or authorized administrators can execute addnetpr (remove execute permission for non-privileged users).
addnetpr (SGI IRIX) executable permissions = restrict to root/administrators - Compensating control
Until a vendor fix is available, restrict untrusted local user access to affected SGI IRIX systems (limit logins, disable unneeded local accounts, and apply host-level access controls) to prevent local users from executing or exploiting addnetpr.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1286?
CVE-1999-1286 has a high severity rating due to the potential for local users to gain root access through a symlink attack.
How do I fix CVE-1999-1286?
To mitigate CVE-1999-1286, users should upgrade to a version of SGI IRIX later than 6.2 or apply appropriate security patches.
What systems are affected by CVE-1999-1286?
CVE-1999-1286 affects SGI IRIX 5.3 and earlier versions up to 6.2.
What is a symlink attack in the context of CVE-1999-1286?
A symlink attack involves creating a symbolic link to a file that a program writes to, allowing unauthorized modifications.
Who can exploit CVE-1999-1286?
CVE-1999-1286 can be exploited by any local user on the system with access to the affected software.