runpriv in SGI IRIX allows local users to bypass intended restrictions and execute arbitrary commands via shell metacharacters in a command line for a privileged binary in /usr/sysadm/privbin.
CVSS Vector
AV:L/AC:L/Au:N/C:C/I:C/A:CSgi Irix
OSSgi6.5.22
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
References
Related vulnerabilities
CVE-2003-0174CRITICAL9.8PL ✓same product
SGI IRIX: logowanie bez hasła przez błąd weryfikacji LDAP (nsd)
CVE-2001-0249CRITICAL9.8PL ✓same product
Heap overflow w FTP daemon — zdalne wykonanie kodu przez komendę LIST
CVE-2001-0248CRITICAL9.8PL ✓same product
Buffer overflow w serwerze FTP na HP-UX 11 via polecenie STAT i glob
CVE-2010-1039HIGH10.0same product
Format string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2...
CVE-2007-4938HIGH7.6same product
Heap-based buffer overflow in libmpdemux/aviheader.c in MPlayer 1.0rc1 and earlier allows remote attackers to ...