SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information

Report a Vulnerability

 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#142228

SGI IRIX vulnerable to DoS when user space program calls the PIOCSWATCH ioctl() function

Overview

A vulnerability in the SGI IRIX PIOCSWATCH ioctl() function may allow local attackers to crash the operating system.

I. Description

SGI states that PIOCSWATCH ioctl "establishes or clears a set of watched areas in the traced process." According to SGI Security Advisory 20030603-01-P, a local attacker could crash the operating system by exploiting this vulnerability:

    It's been reported that non-root users can call the PIOCSWATCH ioctl() in its various invocations via a user space program and crash IRIX with a kernel panic. This could be used as a potential Denial of Service attack on the system. A local account on the system is required.

II. Impact

A local attacker may be able to crash the operating system.

III. Solution

The vendor encourages users to either upgrade to IRIX 6.5.21 (when it becomes available) or apply a patch as described in SGI Security Advisory 20030603-01-P.

Systems Affected

VendorStatusDate NotifiedDate Updated
SGIVulnerable11-Jun-2003

References

http://www.secunia.com/advisories/8996/
ftp://patches.sgi.com/support/free/security/advisories/20030603-01-P
http://techpubs.sgi.com/library/tpl/cgi-bin/getdoc.cgi?coll=0650&db=man&fname=/usr/share/catman/p_man/cat4/proc.z&srch=PIOCSWATCH

Credit

Thanks to SGI for reporting this vulnerability.

This document was written by Ian A Finlay, and is based on information contained within the SGI Security Advisory 20030603-01-P.

Other Information

Date Public:2003-06-10
Date First Published:2003-06-11
Date Last Updated:2003-06-11
CERT Advisory: 
CVE-ID(s):CAN-2003-0175
NVD-ID(s):CAN-2003-0175
US-CERT Technical Alerts: 
Severity Metric:2.16
Document Revision:8

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2003 Carnegie Mellon University
Disclaimers and copyright information
Get a PDF Reader