CVE-2000-0013

IRIX soundplayer - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2000-0013. PoCs published by Loneguard.

AI-analyzed exploit summary This exploit leverages a command injection vulnerability in SGI Irix's 'soundplayer' application, which can be triggered via 'midikeys' (a setuid binary). The PoC compiles a C program to spawn a setuid shell, then guides the user to exploit the vulnerability by saving a file with a malicious filename.

Description

IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which is executed via the midikeys program.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Loneguard · bashlocalirix
https://www.exploit-db.com/exploits/19706

This exploit leverages a command injection vulnerability in SGI Irix's 'soundplayer' application, which can be triggered via 'midikeys' (a setuid binary). The PoC compiles a C program to spawn a setuid shell, then guides the user to exploit the vulnerability by saving a file with a malicious filename.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: SGI Irix soundplayer (via midikeys)
No auth needed
Prerequisites: SGI Irix system with midikeys setuid and soundplayer installed · Local access to the system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (1)

Core 1
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/909

Scores

EPSS 0.0070
EPSS Percentile 48.2%

Details

Status published
Products (1)
sgi/irix 6.2
Published Dec 31, 1999
Tracked Since Feb 18, 2026