H-106Third-party advisoryGovernment resource
http://www.ciac.org/ciac/bulletins/h-106.shtml CVE-1999-0036
HIGH
SGI IRIX 6.4 - 'login' Local Privilege Escalation
Record summary
CVE-1999-0036 has a selected CVSS score of 8.4 (high); EIP currently links 2 catalogued exploits.
Description
IRIX login program with a nonzero LOCKOUT parameter allows creation or damage to files.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Aug 1, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Default status: unknown | CVE List | 5.0 | affected |
| 5.0.1 | affected | ||
| 5.1 | affected | ||
| 5.1.1 | affected | ||
| 5.2 | affected | ||
| 5.3 | affected | ||
| 6.0 | affected | ||
| 6.0.1 | affected | ||
| 6.1 | affected | ||
| 6.2 | affected | ||
| 6.3 | affected | ||
| 6.4 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBSGI IRIX 6.4 - 'login' Local Privilege EscalationExploitDB exploitby David HedleyNot analyzed1 file
ExploitDBSGI IRIX - '/bin/login' Local Buffer OverflowExploitDB exploitby David HedleyNot analyzed1 file
References
4990vdb entry
http://www.osvdb.org/990 sgi-lockout(557)vdb entry
https://exchange.xforce.ibmcloud.com/vulnerabilities/557 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-1999-0036