Junglewise Threat Intelligence

CVE-1999-0030: SGI IRIX root privilege escalation via buffer overflow in xlock

CVE-1999-0030 · Severity: high · CVSS 7.2 · Published 1997-07-16

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A security vulnerability exists in the xlock utility on SGI IRIX operating systems, which is used to lock a user's display. A local user can exploit this flaw to bypass security restrictions and gain full administrative (root) control over the system. This could lead to a complete compromise of the machine, including unauthorized access to all data and system settings.

Technical details

The xlock utility in SGI IRIX contains a buffer overflow vulnerability. By providing specially crafted input to the command, a local attacker can overflow a buffer and execute arbitrary code with elevated privileges. Because xlock is typically installed with setuid root permissions to manage screen locking and authentication, successful exploitation allows a non-privileged local user to gain full root access to the operating system. The vulnerability is triggered locally and does not require prior administrative authentication.

Affected products

  • SGI IRIX

Timeline

  • 1997-07-16: disclosed

References

Related threats