Junglewise Threat Intelligence

CVE-1999-0126: SGI IRIX buffer overflow in xterm and Xaw

CVE-1999-0126 · Severity: high · CVSS 7.2 · Published 1998-05-03

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A security vulnerability exists in the SGI IRIX operating system's terminal emulator and graphical widget library. This flaw could allow a local user to gain full administrative control (root access) over the system. Such an exploit would allow an attacker to access any data on the machine, modify system settings, or disrupt operations.

Technical details

A buffer overflow vulnerability exists in the xterm executable and the Athena Widget Set (Xaw) library on SGI IRIX systems. The flaw is triggered by improper bounds checking when handling input, which can be leveraged by a local attacker to execute arbitrary code with elevated privileges. Because xterm is typically installed with setuid root permissions to manage terminal settings, successful exploitation results in a full privilege escalation to root. The vulnerability is accessible to any user with local shell access to the system. Patches were historically released by SGI to address this issue in the late 1990s.

Affected products

  • SGI IRIX All versions prior to May 1998 patch

Timeline

  • 1998-05-03: disclosed: Initial publication date

References

Related threats