Vulnerability Name:

CVE-1999-1219 (CCN-511)

Assigned:1994-08-01
Published:1994-08-01
Updated:2018-05-03
Summary:Vulnerability in sgihelp in the SGI help system and print manager in IRIX 5.2 and earlier allows local users to gain root privileges, possibly through the clogin command.
CVSS v3 Severity:9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
CVSS v2 Severity:7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
7.2 High (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Complete
Integrity (I): Complete
Availibility (A): Complete
Vulnerability Type:CWE-Other
Vulnerability Consequences:Gain Privileges
References:Source: CCN
Type: AusCERT Advisory AA-94.04a
SGI IRIX 5.x sgihelp vulnerability

Source: CCN
Type: CIAC Information Bulletin E-33
Vulnerabilities in the SGI IRIX Help System

Source: CIAC
Type: Patch, Vendor Advisory
E-33

Source: MITRE
Type: CNA
CVE-1999-1219

Source: CCN
Type: CERT Advisory CA-1994-13
SGI IRIX Help Vulnerability

Source: CERT
Type: Patch, Third Party Advisory, US Government Resource
CA-1994-13

Source: CCN
Type: OSVDB ID: 8557
IRIX SGI Help System / Print Manager sgihelp clogin Local Privilege Escalation

Source: CCN
Type: OSVDB ID: 8558
IRIX sgihelp Root Privilege Escalation

Source: BID
Type: Exploit, Patch, Vendor Advisory
468

Source: CCN
Type: BID-468
IRIX sgihelp Vulnerability

Source: XF
Type: UNKNOWN
sgi-prn-mgr(511)

Source: XF
Type: UNKNOWN
sgi-prn-mgr(511)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sgi:irix:5.1:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.2:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sgi:irix:5.2:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:5.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sgi irix 5.1
    sgi irix 5.2
    sgi irix 5.2
    sgi irix 5.1