Executive brief
A vulnerability in the Csetup utility on SGI IRIX operating systems allows a local user to create or overwrite files anywhere on the system. This could lead to a complete system takeover or permanent data loss by overwriting critical system configuration files. The issue affects older legacy Unix environments and represents a significant risk to system integrity and availability.
Technical details
The Csetup utility in SGI IRIX contains a vulnerability that allows for arbitrary file creation and overwriting. This is typically a result of insecure file handling or symlink vulnerabilities within the utility, which often runs with elevated privileges. A local attacker with access to the system can exploit this flaw to modify sensitive system files, such as /etc/passwd or system binaries, leading to full administrative access (root). The vulnerability is reachable via the local command line and does not require special permissions beyond initial system access.
Affected products
- SGI IRIX
Timeline
- 1997-01-08: disclosed: Initial publication date in NVD