Junglewise Threat Intelligence

CVE-1999-1384: SGI IRIX privilege escalation in Indigo Magic System Tour

CVE-1999-1384 · Severity: high · CVSS 7.2 · Published 1996-10-30

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the SGI IRIX system tour package allows a local user to gain full administrative control of the system. The issue exists in a utility designed to remove the introductory system tour, which runs with elevated privileges. An attacker can exploit this to execute their own malicious code and take over the machine.

Technical details

The vulnerability exists in the 'RemoveSystemTour' binary, which is setuid root. This utility executes the 'inst' command to remove the system tour package. Because 'inst' is highly configurable via environment variables (such as rbase) and user-defined configuration files (.swmgrrc), a local attacker can redirect the 'inst' working directory to a location they control. By placing a malicious '.exitops' script in that directory, the attacker can force the setuid process to execute arbitrary commands with root privileges. The issue affects IRIX versions 5.x through 6.3.

Affected products

  • SGI IRIX 5.x through 6.3

Timeline

  • 1996-10-30: disclosed: Initial discovery and public disclosure on Bugtraq
  • 1996-10-30: advisory: NVD published date

References

Related threats