7.2
CVSSv2

CVE-1999-0959

Published: 01/02/1997 Updated: 03/05/2018
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

IRIX startmidi program allows local users to modify arbitrary files via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 6.0.1

sgi irix 6.1

sgi irix 5

sgi irix 6.0

sgi irix 6.4

sgi irix 6.2

sgi irix 6.3

Exploits

source: wwwsecurityfocuscom/bid/469/info A vulnerability exists in the startmidi program from Silicon Graphics This utility is included with Irix versions 5x and 6x with the Iris Digital Media Execution Environment startmidi is setuid root, and creates a temporary file called /tmp/midipid It does not check to see if this file alread ...