Executive brief
A vulnerability in the 'eject' command of the SGI IRIX operating system allows a local user to gain full administrative control of the system. The 'eject' utility is used to remove removable media like CDs or floppy disks. By exploiting this flaw, an attacker with basic access to the computer can bypass security restrictions to access sensitive data or disrupt operations.
Technical details
A buffer overflow vulnerability exists in the 'eject' command on SGI IRIX systems. The flaw is rooted in improper bounds checking (CWE-119) within the utility, which typically runs with elevated privileges to interact with hardware. A local attacker can exploit this by providing specially crafted input to the command, leading to memory corruption and the execution of arbitrary code. Successful exploitation allows a non-privileged user to escalate their privileges to root.
Affected products
- SGI IRIX
Timeline
- 1997-07-16: disclosed