Executive brief
A security vulnerability in the login/scheme command of SGI IRIX operating systems allows a local user to gain full administrative control of the system. By exploiting a memory handling error, an attacker with basic access can bypass security restrictions to execute commands with root privileges. This could lead to a total compromise of the system, including unauthorized access to all data and the ability to modify or disable system services.
Technical details
A buffer overflow vulnerability exists in the 'scheme' component of the login utility on SGI IRIX systems. The flaw is triggered by providing specially crafted, overly long input to the login/scheme command, which fails to perform adequate bounds checking. Because this utility typically runs with elevated privileges, a local attacker can exploit the overflow to overwrite memory and redirect execution flow to arbitrary code. Successful exploitation results in a complete privilege escalation from a standard user to the root account.
Affected products
- SGI IRIX
Timeline
- 1997-07-16: disclosed