CVE-1999-0328

SGI permissions program - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0328. PoCs published by David Hedley.

AI-analyzed exploit summary This exploit targets a buffer overflow vulnerability in the IRIX permissions program (CVE-1999-0328) to execute arbitrary code with group 'sys' privileges. It uses a crafted buffer to overwrite the return address and inject shellcode.

Description

SGI permissions program allows local users to gain root privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by David Hedley · clocalaix
https://www.exploit-db.com/exploits/19318

This exploit targets a buffer overflow vulnerability in the IRIX permissions program (CVE-1999-0328) to execute arbitrary code with group 'sys' privileges. It uses a crafted buffer to overwrite the return address and inject shellcode.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: SGI IRIX 5.x/6.x permissions program
No auth needed
Prerequisites: Access to the target system · IRIX 6.x environment (stack position issue on 5.x)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/19971103-01-PX

Scores

EPSS 0.0068
EPSS Percentile 47.5%

Details

Status published
Products (11)
sgi/irix 5.0.1
sgi/irix 5.1
sgi/irix 5.1.1
sgi/irix 5.2
sgi/irix 5.3 (2 CPE variants)
sgi/irix 6.0
sgi/irix 6.0.1 (2 CPE variants)
sgi/irix 6.1
sgi/irix 6.2
sgi/irix 6.3
... and 1 more
Published Nov 01, 1997
Tracked Since Feb 18, 2026