7.2
CVSSv2

CVE-1999-1461

Published: 07/05/1997 Updated: 18/10/2016
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

inpview in InPerson on IRIX 5.3 through IRIX 6.5.10 trusts the PATH environmental variable to find and execute the ttsession program, which allows local users to obtain root access by modifying the PATH to point to a Trojan horse ttsession program.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 5.3

sgi irix 6.1

sgi irix 6.2

sgi irix 6.3

sgi irix 6.4

sgi irix 6.5.10

Exploits

source: wwwsecurityfocuscom/bid/381/info The inpview utility, included by SGI in its Irix operating system, contains a vulnerability that will allow any local user to obtain root access inpview is part of the InPerson dektop video conferencing package As it needs to access a video capture device, it is setuid root, and attempts to run ...