SGI IRIX 5.1/5.2 - 'sgihelp' Local Privilege Escalation

Related Vulnerabilities: CVE-1999-1219  
Publish Date: 02 Dec 1996
Author: anonymous
                							

                source: http://www.securityfocus.com/bid/468/info

The sgihelp program, from SGI and included with IRIX 5.1 and 5.2, contains a vulnerability. sgihelp contains an option that allows a user to print to a command. Certain SGI utilities, including PrintStatus, printers, scanners, and a number of others, will call this program without changing their uid to the users, from roots. As such, arbitrary commands can be executed as root using the 'print to command' option of sgihelp.

Run PrintStatus
Press the 'help' button.
Select the 'print to command' option. This will allow you to execute anything as root.