Junglewise Threat Intelligence

CVE-1999-0960: SGI IRIX arbitrary directory creation in cdplayer

CVE-1999-0960 · Severity: high · CVSS 7.2 · Published 1998-03-20

Vendors: Sgi.

Executive brief

The cdplayer utility in the SGI IRIX operating system contains a flaw that allows local users to create directories in restricted areas of the file system. This could allow an unauthorized user to disrupt system operations or potentially gain elevated privileges by placing directories in sensitive locations. This issue affects the integrity and availability of the host system.

Technical details

A vulnerability in the SGI IRIX cdplayer utility allows local attackers to create directories in arbitrary locations on the file system. The issue stems from insufficient validation of command-line arguments, which can be manipulated to specify paths outside of the intended directory structure. Because the utility may run with elevated privileges (such as setuid), a local user can exploit this to bypass standard file system permissions. This can lead to a denial of service or be leveraged as a primitive for further privilege escalation. SGI released security advisory 19980301-01-PX to address this issue.

Affected products

  • SGI IRIX cdplayer

Timeline

  • 1998-03-20: advisory: Initial NVD publication date