Executive brief
A vulnerability in the FLEXlm LicenseManager software on IRIX operating systems allows local users to create unauthorized files and execute arbitrary programs. This component is typically used to manage software licenses across a network. An attacker with local access to the system could exploit this flaw to gain full control over the machine, potentially leading to data theft or a complete system shutdown.
Technical details
A vulnerability exists in Globetrotter FLEXlm LicenseManager versions 4.0 through 5.0 as distributed with SGI IRIX. The flaw allows a local attacker to create arbitrary files and execute programs with elevated privileges. The root cause is likely related to insecure handling of temporary files or environment variables by the license management daemon. Successful exploitation grants the attacker complete control over the affected host (Confidentiality, Integrity, and Availability impact). While the advisory focuses on IRIX, historical records suggest similar impacts may exist on other Unix-like systems using these FLEXlm versions.
Affected products
- SGI IRIX
- Globetrotter Software FLEXlm LicenseManager 4.0 to 5.0
Timeline
- 1997-01-06: disclosed