Vulnerability Name: | CVE-2005-0113 (CCN-18894) | ||||||||
Assigned: | 2005-01-14 | ||||||||
Published: | 2005-01-14 | ||||||||
Updated: | 2017-07-11 | ||||||||
Summary: | inpview in SGI IRIX allows local users to execute arbitrary commands via the SUN_TTSESSION_CMD environment variable, which is executed by inpview without dropping privileges. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.2 High (CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2005-0113 Source: CCN Type: iDEFENSE Security Advisory 01.13.05 SGI IRIX inpview Design Error Vulnerability Source: CCN Type: SA13858 SGI IRIX inpview Privilege Escalation Vulnerability Source: SECUNIA Type: Vendor Advisory 13858 Source: CCN Type: SECTRACK ID: 1012894 SGI InPerson inpview Environment Variable Input Validation Error Lets Local Users Gain Root Privileges Source: SECTRACK Type: UNKNOWN 1012894 Source: IDEFENSE Type: Vendor Advisory 20050113 SGI IRIX inpview Design Error Vulnerability Source: OSVDB Type: UNKNOWN 12915 Source: CCN Type: OSVDB ID: 12915 IRIX inpview Environment Variable Local Privilege Escalation Source: BID Type: UNKNOWN 12259 Source: CCN Type: BID-12259 SGI InPerson Local Privilege Escalation Vulnerability Source: XF Type: UNKNOWN irix-inpview-gain-privileges(18894) Source: XF Type: UNKNOWN irix-inpview-gain-privileges(18894) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |