4.6
CVSSv2

CVE-1999-1120

Published: 04/01/1997 Updated: 10/10/2017
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
VMScore: 465
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

netprint in SGI IRIX 6.4 and previous versions trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix

sgi irix 6.2

sgi irix 6.3

sgi irix 5.3

sgi irix 6.0

sgi irix 6.0.1

sgi irix 6.1

Exploits

source: wwwsecurityfocuscom/bid/395/info A vulnerability exists in the netprint program, shipping with Irix 6x and 5x by Silicon Graphics The netprint program calls the "disable" command via a system() call, without specifying an explicit path Therefore, any program in the path named disable can be executed as user lp % cat > /t ...