CVE-1999-1022
serial_ports administrative program in IRIX 4.x and 5.x trusts the user's PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
- Affected products
- Irix
- Sgi Irix
- = 4, 5.2, 5.3
- Fix
- Available
- CVSS 2.0
- 6.2 MEDIUM
- EPSS
- 0.8% (54th percentile)
- NVD status
- Modified
- Published
- 2001-09-12
CVE-1999-1022 at NVD
1 known exploit for CVE-1999-1022
Proof-of-concept code and exploit modules indexed by Sploitus