CVE

Id
1002  
CVE No.
CVE-1999-1022  
Status
Candidate  
Description
serial_ports administrative program in IRIX 4.x and 5.x trusts the user"s PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.  
Phase
Proposed (20010912)  
Votes
ACCEPT(2) Cole, Frech | NOOP(2) Christey, Foat  
Comments
Christey> Note: CVE-1999-1310 is a duplicate of this candidate. | CVE-1999-1310 will be REJECTed; this is the proper CAN to use. | | CIAC:F-01 | URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml | SGI:19941001-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P | MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html