CVE-1999-0960

IRIX - Unauthenticated Arbitrary Directory Creation via cdplayer Command Line Option

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-0960. PoCs published by Yuri Volobuev.

AI-analyzed exploit summary This exploit leverages a privilege escalation vulnerability in SGI IRIX's cdplayer application, which fails to drop root privileges. By creating a directory and a .rhosts file, an attacker can gain root access via rsh.

Description

IRIX cdplayer allows local users to create directories in arbitrary locations via a command line option.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Yuri Volobuev · textlocalirix
https://www.exploit-db.com/exploits/19262

This exploit leverages a privilege escalation vulnerability in SGI IRIX's cdplayer application, which fails to drop root privileges. By creating a directory and a .rhosts file, an attacker can gain root access via rsh.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Trivial
Reliability
Reliable
Target: SGI IRIX cdplayer (version not specified)
No auth needed
Prerequisites: Access to a vulnerable SGI IRIX system with cdplayer installed · Ability to execute commands on the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/19980301-01-PX

Scores

EPSS 0.0068
EPSS Percentile 47.5%

Details

Status published
Products (7)
sgi/irix 5
sgi/irix 6.0
sgi/irix 6.0.1
sgi/irix 6.1
sgi/irix 6.2
sgi/irix 6.3
sgi/irix 6.4
Published Mar 20, 1998
Tracked Since Feb 18, 2026