Junglewise Threat Intelligence

CVE-1999-1116: SGI IRIX privilege escalation in runpriv

CVE-1999-1116 · Severity: high · CVSS 7.2 · Published 1997-05-03

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the Indigo Magic System Administration subsystem of SGI IRIX operating systems allows a local user to gain full administrative (root) control. This component is responsible for system management tasks, and an exploit could allow an unauthorized individual already on the system to bypass security restrictions, access sensitive data, or disrupt operations.

Technical details

A privilege escalation vulnerability exists in the 'runpriv' executable, which is part of the Indigo Magic System Administration subsystem in SGI IRIX versions 6.3 and 6.4. The flaw allows a local, unprivileged user to execute commands with elevated root privileges. While the specific root cause (e.g., buffer overflow or environment variable manipulation) is not detailed in the summary, the impact is a complete compromise of the local system's integrity, confidentiality, and availability. SGI released patches in 1997 to address this issue.

Affected products

  • SGI IRIX 6.3, 6.4

Timeline

  • 1997-05-03: disclosed
  • 1997-05-03: advisory: SGI security advisory 19970503-01-PX released
  • 1997-05-03: patched

References

Related threats