7.2
CVSSv2

CVE-1999-1384

Published: 30/10/1996 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x up to and including 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 5.1

sgi irix 5.1.1

sgi irix 6.2

sgi irix

sgi irix 5.0

sgi irix 5.0.1

sgi irix 6.0.1

sgi irix 6.1

sgi irix 5

sgi irix 6.0

sgi irix 5.2

sgi irix 5.3

Exploits

source: wwwsecurityfocuscom/bid/470/info A vulnerability exists in both the Systour and OutOfBox susbsystems included with new installs of IRIX 5x and 6x from SGI This vulnerability allows users on the system to run arbitrary commands as root $ rbase=$HOME; export rbase $ mkdir -p $HOME/var/inst $ echo "dryrun: true" > $HOME/swm ...