Executive brief
A vulnerability in the netprint utility of the SGI IRIX operating system allows local users to gain unauthorized administrative privileges. The utility, which manages network printing, incorrectly trusts user-defined search paths when looking for system programs. An attacker can exploit this to trick the system into running malicious code, potentially leading to a full takeover of the affected machine.
Technical details
The netprint utility in SGI IRIX 6.4 and earlier contains a privilege escalation vulnerability due to an insecure system() call. The program attempts to execute the 'disable' command without using an absolute path, relying instead on the PATH environment variable. A local attacker can modify their PATH to point to a malicious executable named 'disable', which netprint will then execute with 'lp' user privileges. Furthermore, by combining this with symlink attacks on the BSD printing subsystem (e.g., /usr/spool/lpd/lpd.lock), an attacker can escalate from 'lp' to root privileges. SGI released patches 1685 and 1686 to address this issue by ensuring the utility no longer relies on untrusted environment variables.
Affected products
- SGI IRIX 6.4 and earlier
Timeline
- 1996-11-01: disclosed: Vulnerability reported to SGI by Yuri Volobuev
- 1996-12-03: patched: SGI released advisory 19961203-01-PX and associated patches
- 1997-01-04: advisory: Public disclosure via Bugtraq mailing list