Executive brief
A critical vulnerability exists in the object server program of SGI IRIX operating systems. This flaw allows a remote attacker to take complete control of the affected system with administrative (root) privileges. Such an exploit could lead to total data loss, unauthorized access to sensitive information, and permanent disruption of business operations.
Technical details
A vulnerability exists in the object server program (part of the IRIS InSight documentation system) on SGI IRIX versions 5.2 through 6.1. The flaw allows for remote privilege escalation to root, likely due to improper handling of requests or environment variables by the server process. An unauthenticated attacker can exploit this over the network to execute arbitrary commands with the highest possible privileges. SGI released security advisory 19960101-01-PX to address this issue, and patches were made available via their support FTP.
Affected products
- SGI IRIX 5.2 through 6.1
Timeline
- 1996-01-01: advisory: SGI security advisory 19960101-01-PX released
- 1996-01-03: disclosed: NVD publication date