Executive brief
A vulnerability in the fsdump utility within the IRIX operating system allows local users to gain full administrative control of the system. By manipulating sensitive system files through this command, an attacker can bypass security restrictions to obtain root-level access. This could lead to a total compromise of the server, including unauthorized data access and system disruption.
Technical details
A privilege escalation vulnerability exists in the fsdump utility of the SGI IRIX operating system. The flaw stems from improper handling of file operations, which allows a local, unprivileged user to modify sensitive system files that should be restricted. By exploiting this behavior, an attacker can escalate their privileges to root. The attack requires local shell access but no special authentication beyond a standard user account. SGI released security advisory 19970301-01-P to address this issue.
Affected products
- SGI IRIX
Timeline
- 1996-12-03: disclosed
- 1997-03-01: advisory: SGI security advisory 19970301-01-P released