Executive brief
A security vulnerability exists in the xlock utility on SGI IRIX operating systems, which is used to lock a user's display. A local user can exploit this flaw to bypass security restrictions and gain full administrative (root) control over the system. This could lead to a complete compromise of the machine, including unauthorized access to all data and system settings.
Technical details
The xlock utility in SGI IRIX contains a buffer overflow vulnerability. By providing specially crafted input to the command, a local attacker can overflow a buffer and execute arbitrary code with elevated privileges. Because xlock is typically installed with setuid root permissions to manage screen locking and authentication, successful exploitation allows a non-privileged local user to gain full root access to the operating system. The vulnerability is triggered locally and does not require prior administrative authentication.
Affected products
- SGI IRIX
Timeline
- 1997-07-16: disclosed