7.2
CVSSv2

CVE-1999-0051

Published: 06/01/1997 Updated: 17/08/2022
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 735
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.

Vulnerable Product Search on Vulmon Subscribe to Product

globetrotter flexlm 4.1

globetrotter flexlm 5.0

sgi irix 6.0.1

sgi irix 5.3

sgi irix 4.0.5_iop

sgi irix 4.0

sgi irix 3.3.2

sgi irix 4.0.5h

sgi irix 4.0.4

sgi irix 4.0.1

sgi irix 6.1

globetrotter flexlm 4.0

sgi irix 5.0.1

sgi irix 4.0.5e

sgi irix 4.0.3

sgi irix 5.1.1

sgi irix 4.0.1t

sgi irix 5.1

sgi irix 4.0.5_ipr

sgi irix 4.0.5a

sgi irix 6.4

sgi license oeo 3.1.1

sgi irix 3.3.3

sgi irix 4.0.5g

sgi irix 5.0

sgi irix 4.0.5f

sgi irix 4.0.2

sgi irix 5.2

sgi license oeo 3.0

sgi license oeo 3.1

sgi irix 4.0.5d

sgi irix 6.2

sgi irix 6.3

sgi irix 4.0.4b

sgi irix 4.0.5

sgi irix 4.0.4t

sgi irix 6.0

sun sunos 4.1.4

sun solaris 2.4

sun solaris 2.5.1

sun solaris 2.5

sun sunos 4.1.4jl

sun sunos 5.5

sun sunos 5.4

sun sunos 4.1.1

sun sunos 5.5.1

sun sunos 4.1.2

sun sunos 4.1.3u1

sun sunos 4.1.3

Exploits

source: wwwsecurityfocuscom/bid/72/info Under normal operation LicenseManager(1M) is a program used to view and manage FLEXlm and NetLS software licenses Unfortunately, a set of vulnerabilities has been discovered that allows LicenseManager(1M) to overwrite root-owned files allowing root access % setenv NETLS_LICENSE_FILE /rhosts % /u ...
source: wwwsecurityfocuscom/bid/73/info Under normal operation LicenseManager(1M) is a program used to view and manage FLEXlm and NetLS software licenses Unfortunately, a set of vulnerabilities has been discovered that allows LicenseManager(1M) to arbitrary manipulate root-owned files allowing root access % mkdir -p /tmp/var/flexlm % s ...
source: wwwsecurityfocuscom/bid/461/info The Solaris License Manager that ships with versions 251 and 26 is vulnerable to multiple symlink attacks License Manager creates lockfiles owned by root and set mode 666 which it writes to regularily It follows symlinks bash$ ls -l /var/tmp/lock* -rw-rw-rw- 1 root root 0 Oct 21 18:24 /var/ ...