Executive brief
A security vulnerability in the SGI IRIX operating system's help and print management systems could allow a local user to gain full administrative control of the computer. By exploiting this flaw, an individual with basic access to the system could bypass security restrictions to view sensitive data, modify system files, or disrupt operations. This issue primarily affects older versions of the IRIX platform used in legacy workstation environments.
Technical details
A privilege escalation vulnerability exists in the 'sgihelp' utility, which is part of the SGI help system and print manager in IRIX versions 5.2 and earlier. The flaw allows a local attacker to execute commands with elevated (root) privileges, potentially leveraging the 'clogin' command as an entry point. Because the affected component likely runs with setuid root or handles system-level requests improperly, an authenticated local user can manipulate the process to break out of restricted environments. This vulnerability is reachable only by users with local shell access. Patches were historically provided by the vendor to address this issue in the mid-1990s.
Affected products
- SGI IRIX 5.2 and earlier
Timeline
- 1994-08-11: disclosed: Initial disclosure and NVD publication
- 1994-12-31: advisory: Included in CERT 1994 annual advisory summary