7.2
CVSSv2

CVE-2000-0013

Published: 31/12/1999 Updated: 10/09/2008
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 725
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.

Vulnerable Product Search on Vulmon Subscribe to Product

sgi irix 6.2

Exploits

#!/bin/sh #source: wwwsecurityfocuscom/bid/909/info # #SGI's Irix operating system ships with an X11 application called 'soundplayer' which is used to play WAV files It is not setuid root by itself, but can inherit root privileges if called by midikeys (which is setuid on some old IRIX systems) Soundplayer is vulnerable to an input vali ...