Executive brief
A security vulnerability exists in the 'pset' command within SGI IRIX operating systems. This command is used for managing processor sets on high-performance computing systems. A local user can exploit this flaw to gain full administrative (root) control over the system, potentially leading to unauthorized data access or system disruption.
Technical details
A buffer overflow vulnerability exists in the 'pset' utility on SGI IRIX systems. The flaw is triggered when the command processes overly long input, leading to memory corruption. Because the 'pset' binary often runs with elevated privileges to manage system processor sets, a local attacker can exploit this overflow to execute arbitrary code and escalate their privileges to root. The attack requires local shell access but no special user permissions. SGI released patches for affected IRIX versions following the initial discovery in 1997.
Affected products
- SGI IRIX
Timeline
- 1997-07-16: disclosed: Initial publication date in NVD