6.2
CVSSv2

CVE-1999-1398

Published: 07/05/1997 Updated: 18/10/2016
CVSS v2 Base Score: 6.2 | Impact Score: 10 | Exploitability Score: 1.9
VMScore: 625
Vector: AV:L/AC:H/Au:N/C:C/I:C/A:C

Vulnerability Summary

Vulnerability in xfsdump in SGI IRIX may allow local users to obtain root privileges via the bck.log log file, possibly via a symlink attack.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 5.0

sgi irix 6.0

sgi irix 6.0.1

sgi irix 5.0.1

sgi irix 5.1

sgi irix 6.1

sgi irix 6.2

sgi irix 5.3

sgi irix 5.1.1

sgi irix 5.2

sgi irix 6.3

sgi irix 6.4

Exploits

source: wwwsecurityfocuscom/bid/472/info The xfsdump program shipped with Irix 5x and 6x from SGI contains a vulnerability which could lead to root compromise By creating a log file in /usr/tmp called bcklog, a user could create a symbolic link from this file to any file they wish to be created as root This is turn could be used to c ...