7.2

CVE-1999-1384

Exploit
Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sgi ≫ Irix Version <= 6.3
Sgi ≫ Irix Version 5
Sgi ≫ Irix Version 5.0
Sgi ≫ Irix Version 5.0.1
Sgi ≫ Irix Version 5.1
Sgi ≫ Irix Version 5.1.1
Sgi ≫ Irix Version 5.2
Sgi ≫ Irix Version 5.3
Sgi ≫ Irix Version 5.3 Edition xfs
Sgi ≫ Irix Version 6.0
Sgi ≫ Irix Version 6.0.1
Sgi ≫ Irix Version 6.0.1 Edition xfs
Sgi ≫ Irix Version 6.1
Sgi ≫ Irix Version 6.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.62% 0.729
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul
Patch
Third Party Advisory
US Government Resource
ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I
Patch
Vendor Advisory
http://marc.info/?l=bugtraq&m=87602167420095&w=2
http://www.iss.net/security_center/static/7456.php
http://www.securityfocus.com/bid/470
Patch
Vendor Advisory
Exploit