SGI IRIX 6.4 - 'rmail' Local Privilege Escalation

Author: Yuri Volobuev
type: local
platform: irix
port: 
date_added: 1997-05-07  
date_updated: 2017-11-22  
verified: 1  
codes: OSVDB-83516  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 19349.txt  
source: https://www.securityfocus.com/bid/460/info

A vulnerability exists in the rmail utility, included by SGI with it's Irix operating system. By failing to sanity check the contents of an environment variable, arbitrary commands may be executed with gid mail. rmail is used with uucp.


The following example is provided:

setenv LOGNAME blah; command-to-execute