gr_osview in SGI IRIX does not drop privileges before opening files, which allows local users to overwrite arbitrary files via the -s option.
Link | Tags |
---|---|
http://securitytracker.com/id?1013662 | vdb entry |
ftp://patches.sgi.com/support/free/security/advisories/20050402-01-P | patch vendor advisory |
http://www.idefense.com/application/poi/display?id=225&type=vulnerabilities | exploit third party advisory patch vendor advisory |
http://secunia.com/advisories/14875 | third party advisory |