|
|
Info |
Last Modified |
| 7 months ago |
|
|
|
|
Description |
IRIX contains a flaw that allows a remote attacker to view files outside of the web path. The issue is due to the wrap script not properly sanitizing user input, specifically directory traversal style attacks (../../).
|
|
Classification |
Location:
Remote/Network Access Required
Attack Type:
Information Disclosure,
Input Manipulation
Impact:
Loss of Confidentiality
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
|
|
Solution |
Silicon Graphics, Inc. has released patches to address this issue. Additionally, it is possible to correct the flaw by implementing the following workaround: either change the permissions of the wrap script or remove the outbox subsystem.
#/bin/chmod 400 /var/www/cgi-bin/wrap
or
# /usr/sbin/versions -v remove outbox
|
|
Products |
|
IRIX
 |
6.2 |
6.3 |
6.4 |
5.3 |
6.0.x |
6.1 |
|
|
|
|
|
|
|
Credit |
- J.A. Gutierrez - spd
GTC1.CPS.UNIZAR.ES -
|
|
BlogsProvided by Technorati
|
None found at this time
|
|
|