Junglewise Threat Intelligence

CVE-1999-1410: SGI IRIX symlink attack in addnetpr

CVE-1999-1410 · Severity: medium · CVSS 6.2 · Published 1997-05-09

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the addnetpr utility, a tool used for managing network printers on SGI IRIX systems, allows local users to overwrite sensitive system files. By exploiting how the utility handles temporary files, an attacker can redirect file operations to critical system locations, potentially leading to a full system takeover or permanent data corruption.

Technical details

The addnetpr utility in SGI IRIX 5.3 and 6.2 contains a race condition vulnerability during the handling of temporary files. Specifically, the program uses a predictable temporary file path (e.g., /var/tmp/printersXXXXXX) without proper atomicity or validation. A local attacker can exploit this by creating a symbolic link from the expected temporary file location to an arbitrary target file (such as /etc/passwd). Because addnetpr runs with elevated privileges (setuid root), it will follow the symlink and overwrite the target file with its own output. This can result in arbitrary file corruption or privilege escalation to root. The vulnerability is exploitable by local users with the ability to run the addnetpr binary.

Affected products

  • SGI IRIX 5.3, 6.2

Timeline

  • 1996-12-03: advisory: SGI security advisory 19961203-02-PX released
  • 1997-05-09: disclosed: Public disclosure on Bugtraq mailing list
  • 1997-05-09: advisory: NVD published date

References

Related threats