Executive brief
A vulnerability in the SGI syserr utility allows local users to corrupt system files. This program is typically used for managing system error logs on SGI workstations. An attacker with existing access to the system could exploit this to damage critical files, potentially leading to system instability or data loss.
Technical details
The SGI syserr utility contains a vulnerability that allows local users to corrupt arbitrary files on the system. The issue likely stems from insecure file handling or improper permission management within the syserr program, which is used for processing system error messages. An attacker with local shell access can leverage this flaw to overwrite or corrupt files they would otherwise not have permission to modify. This can result in a loss of data integrity or a denial-of-service condition if critical system files are targeted. SGI released security advisory 19971103-01-PX to address this issue.
Affected products
- SGI IRIX
Timeline
- 1997-11-01: disclosed
- 1997-11-03: advisory: SGI security advisory 19971103-01-PX released.