CVE
- Id
- 1002
- CVE No.
- CVE-1999-1022
- Status
- Candidate
- Description
- serial_ports administrative program in IRIX 4.x and 5.x trusts the user"s PATH environmental variable to find and execute the ls program, which allows local users to gain root privileges via a Trojan horse ls program.
- Phase
- Proposed (20010912)
- Votes
- ACCEPT(2) Cole, Frech | NOOP(2) Christey, Foat
- Comments
- Christey> Note: CVE-1999-1310 is a duplicate of this candidate. | CVE-1999-1310 will be REJECTed; this is the proper CAN to use. | | CIAC:F-01 | URL:http://ciac.llnl.gov/ciac/bulletins/f-01.shtml | SGI:19941001-01-P | URL:ftp://patches.sgi.com/support/free/security/advisories/19941001-01-P | MISC:http://www.netsys.com/firewalls/firewalls-9410/0019.html