First published: Wed Apr 08 1998(Updated: )
(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =6.3 | |
=6.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-1999-1501 is classified as a local privilege escalation vulnerability that can allow arbitrary command execution.
To fix CVE-1999-1501, ensure the IFS environmental variable is properly cleared before executing any system calls in the affected applications.
CVE-1999-1501 affects the SGI IRIX operating system version 6.3.
No, CVE-1999-1501 can only be exploited by local users with access to the affected system.
Exploiting CVE-1999-1501 can allow an attacker to execute arbitrary commands on the affected system, potentially leading to system compromise.