First published: Fri Jan 14 2005(Updated: )
inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SGI IRIX | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-0113 is rated as a high severity vulnerability due to its potential for unauthorized command execution by local users.
To mitigate CVE-2005-0113, it is recommended to either remove the SUN_TTSESSION_CMD environment variable or restrict access to the inpview application.
CVE-2005-0113 affects local users of SGI IRIX version 6.5 who have access to the inpview application.
CVE-2005-0113 is a command execution vulnerability that allows local users to execute arbitrary commands.
CVE-2005-0113 cannot be exploited remotely as it requires local access to the system.