CVE-1999-1120

SGI IRIX <6.4 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-1120. PoCs published by Yuri Volobuev.

AI-analyzed exploit summary This exploit leverages a path-based vulnerability in the netprint program on Irix 6.x and 5.x, allowing arbitrary command execution as the 'lp' user. It also describes a method to escalate privileges to root by manipulating the BSD printing subsystem.

Description

netprint in SGI IRIX 6.4 and earlier trusts the PATH environmental variable for finding and executing the disable program, which allows local users to gain privileges.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Yuri Volobuev · textlocalirix
https://www.exploit-db.com/exploits/19313

This exploit leverages a path-based vulnerability in the netprint program on Irix 6.x and 5.x, allowing arbitrary command execution as the 'lp' user. It also describes a method to escalate privileges to root by manipulating the BSD printing subsystem.

Classification
Working Poc 95%
Attack Type
Rce | Lpe
Complexity
Moderate
Reliability
Reliable
Target: Irix 6.x and 5.x netprint
No auth needed
Prerequisites: Access to a vulnerable Irix system · Ability to write files to the filesystem
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=87602167420403&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/993
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/395
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/2107
Patch, Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/19961203-02-PX
Vendor Advisory vendor-advisory x_refsource_sgi
ftp://patches.sgi.com/support/free/security/advisories/19961203-01-PX

Scores

EPSS 0.0084
EPSS Percentile 53.2%

Details

Status published
Products (7)
sgi/irix 5.3
sgi/irix 6.0
sgi/irix 6.0.1
sgi/irix 6.1
sgi/irix 6.2
sgi/irix 6.3
sgi/irix < 6.4
Published Jan 04, 1997
Tracked Since Feb 18, 2026