Vulnerability Name: | CVE-1999-1492 (CCN-2103) | ||||||||
Assigned: | 1998-05-27 | ||||||||
Published: | 1998-05-27 | ||||||||
Updated: | 2017-12-19 | ||||||||
Summary: | Vulnerability in (1) diskperf and (2) diskalign in IRIX 6.4 allows local attacker to create arbitrary root owned files, leading to root privileges. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: SGI Security Advisory 19980502-01-P3030 IRIX 6.4 diskperf/diskalign Vulnerabilities Source: SGI Type: Patch, Vendor Advisory 19980502-01-P3030 Source: MITRE Type: CNA CVE-1999-1039 Source: MITRE Type: CNA CVE-1999-1492 Source: CCN Type: OSVDB ID: 8565 IRIX diskperf Arbitrary File Create Privilege Escalation Source: CCN Type: OSVDB ID: 8566 IRIX diskalign Arbitrary File Create Privilege Escalation Source: BID Type: Patch, Vendor Advisory 348 Source: CCN Type: BID-348 IRIX diskalign/diskperf Vulnerabilities Source: XF Type: UNKNOWN sgi-diskperf(2103) Source: XF Type: UNKNOWN sgi-diskperf(2103) Source: XF Type: UNKNOWN sgi-diskalign(2104) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
Vulnerability Name: | CVE-1999-1492 (CCN-2104) | ||||||||
Assigned: | 1998-05-27 | ||||||||
Published: | 1998-05-27 | ||||||||
Updated: | 1998-05-27 | ||||||||
Summary: | Patches 2291 and 2848 for IRIX introduced the diskalign(1) utility, which is used to configure IRIX for data streaming applications. A vulnerability in the diskalign tool could allow a local attacker to create arbitrary root owned files and ultimately gain root privileges. This vulnerability also affects the diskperf(1) command introduced in the same patches. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: CCN Type: SGI Security Advisory 19980502-01-P3030 IRIX 6.4 diskperf/diskalign Vulnerabilities Source: MITRE Type: CNA CVE-1999-1492 Source: CCN Type: BID-348 IRIX diskalign/diskperf Vulnerabilities Source: XF Type: UNKNOWN sgi-diskalign(2104) | ||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||
BACK |