Executive brief
A security vulnerability exists in the mailx utility on SGI IRIX systems, which is a standard command-line tool for managing electronic mail. An attacker with local access to the system could exploit this flaw to potentially gain unauthorized privileges or disrupt system operations. This could lead to a compromise of data integrity and confidentiality on the affected workstation or server.
Technical details
A buffer overflow vulnerability exists within the mailx utility on SGI IRIX. The flaw is triggered when the application fails to properly validate the length of input data before copying it into a fixed-size buffer. A local attacker can exploit this by providing specially crafted input to the mailx program, leading to memory corruption. Successful exploitation can allow the attacker to execute arbitrary code with the privileges of the mailx process, which often runs with elevated permissions, or cause the application to crash. SGI released security advisories and patches (e.g., 19980605-01-PX) to address this issue.
Affected products
- SGI IRIX Not specified
Timeline
- 1998-01-25: disclosed
- 1998-01-25: advisory: NVD Published Date
- 1998-06-05: patched: SGI security advisory date referenced in patches link