Vulnerability Name:

CVE-2005-0464 (CCN-20004)

Assigned:2005-04-07
Published:2005-04-07
Updated:2008-09-05
Summary:gr_osview in SGI IRIX 6.5.22, and possibly other 6.5 versions, does not drop privileges when opening description files while in debug mode, which allows local users to read a line from arbitrary files via the -d and -D options, which prints the line as a formatting error.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Obtain Information
References:Source: SGI
Type: Patch
20050402-01-P

Source: CCN
Type: SGI Security Advisory 20050402-01-P
gr_osview vulnerabilities

Source: MITRE
Type: CNA
CVE-2005-0464

Source: CCN
Type: SA14875
SGI IRIX gr_osview Privilege Escalation and Information Disclosure

Source: SECUNIA
Type: UNKNOWN
14875

Source: CCN
Type: SECTRACK ID: 1013662
SGI IRIX gr_osview Lets Local Users Obtain Sensitive Information and Overwrite Arbitrary Files

Source: SECTRACK
Type: UNKNOWN
1013662

Source: CCN
Type: CIAC INFORMATION BULLETIN P-172
SGI IRIX gr_osview File Overwrite Vulnerabilities

Source: CCN
Type: iDEFENSE Security Advisory 04.07.05
SGI IRIX gr_osview Information Disclosure Vulnerability

Source: IDEFENSE
Type: Patch, Vendor Advisory
20050407 SGI IRIX gr_osview Information Disclosure Vulnerability

Source: OSVDB
Type: UNKNOWN
15351

Source: CCN
Type: OSVDB ID: 15351
IRIX gr_osview -D Parameter Arbitrary File Segment Disclosure

Source: CCN
Type: BID-13057
SGI IRIX GR_OSView Information Disclosure Vulnerability

Source: XF
Type: UNKNOWN
irix-grosview-information-disclosure(20004)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:sgi:irix:6.5.22:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:sgi:irix:6.5.24:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.22:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.23:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.25:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.21m:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.21f:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.26:*:*:*:*:*:*:*
  • OR cpe:/o:sgi:irix:6.5.27:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    sgi irix 6.5.22
    sgi irix 6.5.24
    sgi irix 6.5.22
    sgi irix 6.5.23
    sgi irix 6.5.25
    sgi irix 6.5.21m
    sgi irix 6.5.21f
    sgi irix 6.5.26
    sgi irix 6.5.27