Exploit SGI IRIX 6.4 - 'rmail' Local Privilege Escalation

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
19349
Проверка EDB
  1. Пройдено
Автор
YURI VOLOBUEV
Тип уязвимости
LOCAL
Платформа
IRIX
CVE
null
Дата публикации
1997-05-07
SGI IRIX 6.4 - 'rmail' Local Privilege Escalation
Код:
source: https://www.securityfocus.com/bid/460/info

A vulnerability exists in the rmail utility, included by SGI with it's Irix operating system. By failing to sanity check the contents of an environment variable, arbitrary commands may be executed with gid mail. rmail is used with uucp.


The following example is provided:

setenv LOGNAME blah; command-to-execute
 
Источник
www.exploit-db.com

Похожие темы