Junglewise Threat Intelligence

CVE-1999-0059: SGI IRIX information disclosure in fam service

CVE-1999-0059 · Severity: high · CVSS 7.3 · Published 1997-07-14

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

The File Alteration Monitor (fam) service in the SGI IRIX operating system contains a flaw that allows remote users to view a complete list of files on the server. This exposure of the file system structure can help an attacker identify sensitive data locations or system configurations, potentially leading to further targeted attacks. This affects older systems running the IRIX operating system.

Technical details

The File Alteration Monitor (fam) service in SGI IRIX is vulnerable to an information disclosure flaw. By interacting with the service over the network, an unauthenticated attacker can retrieve a directory listing of all files residing on the server. This vulnerability is categorized under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The root cause is a lack of proper access control or authentication within the fam service when responding to file monitoring requests. This allows an attacker to map the entire file system remotely without valid credentials.

Affected products

  • SGI IRIX

Timeline

  • 1997-07-14: disclosed: Initial publication date in NVD.

References

Related threats