Executive brief
A vulnerability in the 'handler' CGI program on SGI IRIX systems allows remote attackers to execute unauthorized commands. This component is part of the web server infrastructure, and an exploit could allow a complete takeover of the server, leading to data theft or service disruption. Organizations using legacy IRIX systems should apply available patches immediately to prevent unauthorized access.
Technical details
The 'handler' CGI script, typically located in the web server's executable directory on SGI IRIX systems, fails to properly sanitize user input. This lack of validation allows a remote, unauthenticated attacker to inject and execute arbitrary shell commands with the privileges of the web server process. The vulnerability is exploitable via a specially crafted HTTP request. SGI released security advisory 19970501-02-PX and associated patches to address this issue by correcting the input handling logic in the CGI program.
Affected products
- SGI IRIX
Timeline
- 1997-05-01: advisory: SGI security advisory 19970501-02-PX released
- 1997-09-01: disclosed: NVD publication date