Junglewise Threat Intelligence

CVE-1999-0036: SGI IRIX arbitrary file creation in login program

CVE-1999-0036 · Severity: high · CVSS 8.4 · Published 1997-05-26

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the login system of SGI IRIX operating systems allows local users to bypass security controls. By exploiting a specific configuration in the login program, an attacker can create or modify sensitive system files. This could lead to a total loss of system integrity, unauthorized data access, or a complete system takeover.

Technical details

The vulnerability exists in the IRIX 'login' utility when the LOCKOUT parameter is set to a non-zero value. This parameter is intended to manage account lockouts after failed attempts, but a flaw in its implementation allows for arbitrary file creation or modification. An attacker with local access can leverage this flaw to overwrite critical system files or create new ones with elevated privileges. This is categorized as an unrestricted file upload/creation issue (CWE-434) within the context of the login process. Patches were released by SGI in May 1997 to address this behavior.

Affected products

  • SGI IRIX All versions prior to May 1997 patches

Timeline

  • 1997-05-08: advisory: SGI released security advisory 19970508-02-PX
  • 1997-05-26: disclosed: Vulnerability published in NVD

References

Related threats