Junglewise Threat Intelligence

CVE-1999-0959: SGI IRIX arbitrary file modification in startmidi via symlink attack

CVE-1999-0959 · Severity: high · CVSS 7.2 · Published 1997-02-01

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the startmidi utility of the IRIX operating system allows local users to modify sensitive system files. By exploiting how the program handles temporary files, an attacker can gain unauthorized access to or corrupt critical data, potentially leading to a full system takeover. This poses a significant risk to the integrity and availability of the affected workstation or server.

Technical details

The startmidi program in SGI IRIX contains a symlink vulnerability that occurs when the utility handles files without proper validation of the file path. A local attacker can create a symbolic link from a temporary file location used by startmidi to a sensitive system file (such as /etc/passwd). When startmidi is executed, it follows the link and performs write operations on the target file with the privileges of the startmidi process, typically resulting in arbitrary file modification or privilege escalation. This is a classic local race condition or insecure temporary file handling flaw. Patches were historically made available by SGI to address this issue.

Affected products

  • SGI IRIX

Timeline

  • 1997-02-01: disclosed: Initial publication date listed in NVD
  • 1998-03-01: advisory: SGI security advisory date referenced in patches link

References

Related threats