7.2
CVSSv2

CVE-1999-1399

Published: 20/08/1997 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME environmental variable to contain the commands to be executed.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 6.2

Exploits

source: wwwsecurityfocuscom/bid/471/info The SpaceBall game, shipped with Irix 62 from Silicon Graphics contains a security hole which could result in the compromise of the root account By blindly taking the contents of the $HOSTNAME variable, and not placing quotes around it, the spaceballsh program can be made to execute commands # ...