SGI Information for VU#569272

System V derived login contains a remotely exploitable buffer overflow



Vendor Statement

SGI Security Advisory

Title: Buffer Overflow in System V Derived Login
Number: 20011201-01-I
Reference: CERTŪ Advisory CA-2001-34
Date: December 17, 2001

--- Issue Specifics ---

login is a program that local and remote connection mechanisms often
invoke to facilitate logging into a Unix system.

A vulnerability has been discovered in the login program for many
System V-derived Unix implementations that allows unauthorized root
access. More details can be found in CERT advisory CA-2001-34:

Silicon Graphics has investigated the issue and finds that IRIX 3.x may
have had this issue, as mentioned in the CERT advisory. Any versions of
IRIX that are more current than IRIX 3.x, including IRIX 4.x, IRIX 5.x,
and IRIX 6.x, do NOT have this login vulnerability, and no further action
is required.

--- Acknowledgments ----

SGI wishes to thank CERT and the Internet Community at large for
their assistance in this matter.

