Junglewise Threat Intelligence

CVE-1999-0328: SGI permissions program privilege escalation

CVE-1999-0328 · Severity: high · CVSS 7.2 · Published 1997-11-01

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the SGI permissions utility allows a local user to bypass security restrictions and gain full administrative control over the system. This could lead to the unauthorized access of sensitive data, system-wide outages, or the installation of malicious software. The issue affects older SGI operating systems where the permissions program does not correctly handle user requests.

Technical details

A privilege escalation vulnerability exists in the SGI 'permissions' program. The flaw allows a local, unprivileged user to execute commands or manipulate system files with root-level authority. The root cause is likely an insecure handling of permissions or a buffer overflow within the utility, though specific code-level details are limited in historical records. An attacker must have local shell access to the system to exploit this vulnerability. SGI released security advisory 19971103-01-PX to address this issue.

Affected products

  • SGI IRIX

Timeline

  • 1997-11-01: disclosed
  • 1997-11-03: advisory: SGI security advisory 19971103-01-PX released

Related threats