Junglewise Threat Intelligence

CVE-1999-0029: SGI IRIX root privilege escalation in ordist command

CVE-1999-0029 · Severity: high · CVSS 8.4 · Published 1997-07-16

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A security vulnerability exists in the ordist command on SGI IRIX operating systems. This flaw allows a local user to gain full administrative (root) control over the system. An attacker with basic access to the machine could exploit this to bypass security restrictions, access sensitive data, or disrupt operations.

Technical details

A buffer overflow vulnerability exists in the 'ordist' command, a utility found in SGI IRIX systems. The flaw is triggered when the command handles specially crafted input, leading to memory corruption. A local, unprivileged attacker can exploit this vulnerability to execute arbitrary code with elevated privileges. Successful exploitation results in a complete compromise of the host system by granting the attacker root access. The vulnerability is categorized as an out-of-bounds memory safety issue.

Affected products

  • SGI IRIX

Timeline

  • 1997-07-16: disclosed: Initial publication date

References

Related threats