Executive brief
A vulnerability in the SGI IRIX System Manager (sysmgr) allows remote attackers to execute unauthorized commands on a target system. This occurs when a user opens a malicious file, often delivered via email, that the system's mail handler incorrectly processes as a legitimate administrative task. Successful exploitation could lead to a full system compromise, allowing an attacker to access sensitive data or disrupt operations.
Technical details
The vulnerability exists in the SGI IRIX System Manager (sysmgr) GUI due to the way it handles specific MIME types. When a user's Mailcap configuration supports 'x-sgi-task' or 'x-sgi-exec' types, the system may automatically execute commands defined in 'runtask' or 'runexec' descriptor files provided by a remote attacker. This is essentially a remote command execution vulnerability triggered by a trojan horse file. An attacker can exploit this by sending a specially crafted file to a user who then opens it with a vulnerable mail client or browser. Patches were released by SGI in 1998 to address this issue.
Affected products
- SGI IRIX 6.3, 6.4
Timeline
- 1998-04-02: disclosed
- 1998-04-03: patched: SGI released security advisories 19980403-01-PX and 19980403-02-PX.