Executive brief
A vulnerability in the SGI Desktop Permissions Tool allows local users to change the permissions of any file on the system. This could allow a standard user to gain administrative privileges or access sensitive data by modifying system files. The issue affects older versions of the IRIX operating system.
Technical details
A privilege escalation vulnerability exists in the SGI Desktop Permissions Tool within IRIX 6.0.1 and earlier. The tool fails to properly restrict permission modifications, allowing a local, unprivileged attacker to change the access controls of arbitrary files on the filesystem. By targeting sensitive system files or binaries, an attacker can escalate their privileges to root. This is a local attack requiring shell access to the system. Patches were historically released by SGI to address this issue.
Affected products
- SGI IRIX 6.0.1 and earlier
Timeline
- 1995-03-01: advisory: SGI security advisory 19950301-01-P373 released
- 1995-03-03: disclosed: NVD publication date