Junglewise Threat Intelligence

CVE-1999-1272: SGI IRIX buffer overflow in CDROM Confidence Test program

CVE-1999-1272 · Severity: high · CVSS 7.2 · Published 1998-03-01

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A security vulnerability exists in the CDROM Confidence Test utility, a diagnostic tool used to verify the functionality of CD-ROM drives. A local user with access to the system can exploit this flaw to bypass security restrictions and gain full administrative (root) control. This could lead to a complete compromise of the system, including unauthorized access to all data and the ability to modify or delete critical system files.

Technical details

The CDROM Confidence Test program (cdrom) contains multiple buffer overflow vulnerabilities. Because this diagnostic utility often runs with elevated privileges to interact directly with hardware, a local attacker can provide specially crafted input to overflow internal buffers and execute arbitrary code. Successful exploitation allows a non-privileged local user to escalate their privileges to root. The vulnerability was originally identified in SGI IRIX systems, and patches were released by the vendor in early 1998.

Affected products

  • SGI IRIX All versions prior to March 1998 advisory

Timeline

  • 1998-03-01: disclosed: Initial security advisory released by SGI
  • 1998-03-01: patched: SGI released patches for affected systems

References

Related threats