System Manager sysmgr GUI in SGI IRIX 6.4 and 6.3 allows remote attackers to execute commands by providing a trojan horse (1) runtask or (2) runexec descriptor file, which is used to execute a System Manager Task when the user's Mailcap entry supports the x-sgi-task or x-sgi-exec type.
Link | Tags |
---|---|
http://www.osvdb.org/8556 | vdb entry |
ftp://patches.sgi.com/support/free/security/advisories/19980403-02-PX | patch vendor advisory |
ftp://patches.sgi.com/support/free/security/advisories/19980403-01-PX | patch vendor advisory |
http://www.iss.net/security_center/static/809.php | vdb entry |