Junglewise Threat Intelligence

CVE-1999-1494: SGI IRIX arbitrary file read in colorview

CVE-1999-1494 · Severity: low · CVSS 2.1 · Published 1994-08-09

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the colorview utility on Silicon Graphics IRIX systems allows a local user to read files they should not have access to. By using a specific command-line argument, an attacker can view the contents of sensitive system or user files, potentially leading to the exposure of confidential information. This issue affects older versions of the IRIX operating system.

Technical details

The colorview utility in SGI IRIX versions 5.1, 5.2, and 6.0 contains an information disclosure vulnerability. The root cause is improper input validation or insufficient permission checks when processing the '-text' command-line argument. A local attacker with shell access can exploit this by passing a sensitive file path to the argument, causing the utility to display the file's contents regardless of the user's standard file permissions. This allows for the unauthorized reading of arbitrary system files. Patches were historically made available by the vendor (SGI) in 1995.

Affected products

  • SGI IRIX 5.1, 5.2, 6.0

Timeline

  • 1994-08-09: disclosed
  • 1995-02-09: patched: SGI released security advisory 19950209-01-P

References

Related threats