Executive brief
A vulnerability in the SGI permissions utility allows a local user to bypass security restrictions and gain full administrative control over the system. This could lead to the unauthorized access of sensitive data, system-wide outages, or the installation of malicious software. The issue affects older SGI operating systems where the permissions program does not correctly handle user requests.
Technical details
A privilege escalation vulnerability exists in the SGI 'permissions' program. The flaw allows a local, unprivileged user to execute commands or manipulate system files with root-level authority. The root cause is likely an insecure handling of permissions or a buffer overflow within the utility, though specific code-level details are limited in historical records. An attacker must have local shell access to the system to exploit this vulnerability. SGI released security advisory 19971103-01-PX to address this issue.
Affected products
- SGI IRIX
Timeline
- 1997-11-01: disclosed
- 1997-11-03: advisory: SGI security advisory 19971103-01-PX released