Vulnerability Note VU#20851
SGI IRIX df buffer overflow in directory argument
Overview
Description
The df program is used to display statistics about the amount of used and free disc space on a set of mounted file systems. Alternately, it can be used to check on the amount of space available on unmounted block devices which may be specified by some path. |
Impact
This vulnerability may allow local users to gain root privileges. |
Solution
Apply the patched provided by SGI. |
1. Remove setuid perms, and execute perms from df. % chmod u-s `which df` |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| SGI | Vulnerable | - | 20 Apr 2002 |
| SGI | Vulnerable | - | 20 Apr 2002 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- ftp://sgigate.sgi.com/security/19970505-01-A
- ftp://sgigate.sgi.com/security/19970505-02-PX
- ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-97.19.IRIX.df.buffer.overflow.vul
- ftp://ftp.auscert.org.au/pub/auscert/tools/overflow_wrapper/overflow_wrapper.c
- http://xforce.iss.net/static/440.php
Credit
This document was written by Jeff S Havrilla.
Other Information
- CVE IDs: CVE-1999-0025
- CERT Advisory: CA-1997-21
- Date Public: 24 May 97
- Date First Published: 15 Dec 2000
- Date Last Updated: 15 Dec 2000
- Severity Metric: 14.06
- Document Revision: 7
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify