CVE-1999-1410: Medium severity SGI IRIX vulnerability
addnetpr in IRIX 5.3 and 6.2 allows local users to overwrite arbitrary files and possibly gain root privileges via a symlink attack on the printers temporary file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
SGI IRIX addnetprfrom your environment.Uninstall or remove the addnetpr program to prevent local users from exploiting the symlink vulnerability against the printers temporary file. If removal is not feasible, disable or restrict execution of addnetpr to trusted administrators only.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1410?
CVE-1999-1410 is considered to have high severity due to the potential for local users to gain root privileges.
How do I fix CVE-1999-1410?
Fixing CVE-1999-1410 involves applying security patches provided by SGI and ensuring proper permissions are set on temporary files.
What software versions are affected by CVE-1999-1410?
CVE-1999-1410 affects multiple versions of IRIX, including 5.0, 5.1, 5.2, 5.3, 6.0.1, 6.1, and 6.2.
What kind of attack is described in CVE-1999-1410?
CVE-1999-1410 describes a symlink attack that allows local users to overwrite arbitrary files.
Can I exploit CVE-1999-1410 remotely?
CVE-1999-1410 is a local vulnerability and cannot be exploited remotely.