SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#142228

SGI IRIX vulnerable to DoS when user space program calls the PIOCSWATCH ioctl() function

Overview

A vulnerability in the SGI IRIX PIOCSWATCH ioctl() function may allow local attackers to crash the operating system.

I. Description

SGI states that PIOCSWATCH ioctl "establishes or clears a set of watched areas in the traced process." According to SGI Security Advisory 20030603-01-P, a local attacker could crash the operating system by exploiting this vulnerability:

    It's been reported that non-root users can call the PIOCSWATCH ioctl() in its various invocations via a user space program and crash IRIX with a kernel panic. This could be used as a potential Denial of Service attack on the system. A local account on the system is required.

II. Impact

A local attacker may be able to crash the operating system.

III. Solution

The vendor encourages users to either upgrade to IRIX 6.5.21 (when it becomes available) or apply a patch as described in SGI Security Advisory 20030603-01-P.

Systems Affected

VendorStatusDate NotifiedDate Updated
SGIVulnerable11-Jun-2003

References

http://www.secunia.com/advisories/8996/
ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P
http://techpubs.sgi.com/library/tpl/cgi-bin/getdoc.cgi?coll=0650&db=man&fname=/usr/share/catman/p_man/cat4/proc.z&srch=PIOCSWATCH

Credit

Thanks to SGI for reporting this vulnerability.

This document was written by Ian A Finlay, and is based on information contained within the SGI Security Advisory 20030603-01-P.

Other Information

Date Public:2003-06-10
Date First Published:2003-06-11
Date Last Updated:2003-06-11
CERT Advisory: 
CVE-ID(s):CAN-2003-0175
NVD-ID(s):CAN-2003-0175
US-CERT Technical Alerts: 
Metric:2.16
Document Revision:8

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader