Executive brief
A vulnerability in the SpaceWare driver software for IRIX systems allows a local user to take complete control of the computer. By manipulating a specific system setting, an attacker can trick the software into running unauthorized commands with administrative privileges. This could lead to a total compromise of the system, including the theft of sensitive data or the installation of malicious software.
Technical details
A privilege escalation vulnerability exists in the spaceball utility within SpaceWare 7.3 v1.0 on SGI IRIX 6.2. The application fails to properly sanitize or validate the HOSTNAME environment variable before using it in a manner that leads to command execution. A local, unprivileged attacker can set the HOSTNAME variable to contain arbitrary shell commands and then execute the spaceball program. Because the program runs with elevated privileges (likely setuid root or via a privileged script), the injected commands are executed as the root user. This allows for full system compromise, including unauthorized file modification and administrative access.
Affected products
- Spacetec SpaceWare 7.3 v1.0
- SGI IRIX 6.2
Timeline
- 1997-08-20: disclosed: Initial disclosure on Bugtraq mailing list
- 1997-08-20: advisory: NVD publication date