Executive brief
The File Alteration Monitor (fam) service in the SGI IRIX operating system contains a flaw that allows remote users to view a complete list of files on the server. This exposure of the file system structure can help an attacker identify sensitive data locations or system configurations, potentially leading to further targeted attacks. This affects older systems running the IRIX operating system.
Technical details
The File Alteration Monitor (fam) service in SGI IRIX is vulnerable to an information disclosure flaw. By interacting with the service over the network, an unauthenticated attacker can retrieve a directory listing of all files residing on the server. This vulnerability is categorized under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The root cause is a lack of proper access control or authentication within the fam service when responding to file monitoring requests. This allows an attacker to map the entire file system remotely without valid credentials.
Affected products
- SGI IRIX
Timeline
- 1997-07-14: disclosed: Initial publication date in NVD.