(1) ipxchk and (2) ipxlink in SGI OS2 IRIX 6.3 does not properly clear the IFS environmental variable before executing system calls, which allows local users to execute arbitrary commands.
Link | Tags |
---|---|
http://marc.info/?l=bugtraq&m=89217373930054&w=2 | mailing list |
http://www.securityfocus.com/bid/70 | vdb entry patch vendor advisory |
http://www.securityfocus.com/bid/71 | vdb entry patch vendor advisory |