Junglewise Threat Intelligence

CVE-1999-1554: SGI IRIX incorrect GID setting in Mail utility

CVE-1999-1554 · Severity: low · CVSS 2.1 · Published 1990-10-31

Technologies: Sgi Irix. Vendors: Sgi.

Executive brief

A vulnerability in the Mail utility on older SGI IRIX operating systems allows local users to access and read the private emails of other users on the same system. This occurs because the application fails to correctly manage user permissions when it is launched. This could lead to the exposure of sensitive personal or corporate information to unauthorized individuals with access to the machine.

Technical details

The /usr/sbin/Mail utility in SGI IRIX versions 3.3 and 3.3.1 contains a privilege management vulnerability. The application does not properly set the effective group ID (GID) to the GID of the user who initiated the process. Because the Mail utility typically runs with elevated privileges to access system mail spools, this failure to drop or correctly transition privileges allows a local attacker to bypass standard file permission checks. Consequently, an authenticated local user can read the mail files belonging to other users on the system. Patches were historically made available by the vendor to address this issue.

Affected products

  • SGI IRIX 3.3, 3.3.1

Timeline

  • 1990-10-31: disclosed
  • 1990-10-31: advisory: Initial NVD publication date

References

Related threats