First published: Wed Aug 20 1997(Updated: )
spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =6.2 | |
=6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1399 is classified as a local privilege escalation vulnerability allowing users to gain root privileges.
To fix CVE-1999-1399, ensure that users do not have the ability to set the HOSTNAME environmental variable to execute arbitrary commands.
CVE-1999-1399 affects the Spaceball program in SpaceWare 7.3 on SGI IRIX 6.2.
CVE-1999-1399 is a local vulnerability, meaning it cannot be exploited remotely without local access.
Exploiting CVE-1999-1399 can lead to full system compromise with root access to the affected system.