Junglewise Threat Intelligence

CVE-1999-1401: SGI IRIX insecure file permissions in Desktop searchbook

CVE-1999-1401 · Severity: medium · CVSS 4.6 · Published 1996-12-05

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the Desktop searchbook utility on SGI IRIX systems allows for insecure file permissions. This could allow a local user to gain unauthorized access to or modify specific system files, potentially compromising the integrity of the workstation. This affects older versions of the IRIX operating system commonly used in high-performance computing environments.

Technical details

The vulnerability stems from improper permission settings (insecure DAC) by the Desktop searchbook program in SGI IRIX versions 5.0.x through 6.2. Specifically, the 'iconbook' and 'searchbook' files are created or maintained with permissions that allow unauthorized local users to read or write to them. An attacker with local access to the system can exploit this to manipulate these files, potentially leading to a loss of confidentiality, integrity, or availability of the affected components. SGI released patches (e.g., 19961201-01-PX) to address this issue by enforcing stricter file permissions.

Affected products

  • SGI IRIX 5.0.x through 6.2

Timeline

  • 1996-12-05: disclosed: Initial publication of the vulnerability details.
  • 1996-12-01: patched: SGI released security advisory and patches.

References

Related threats