IRIX handler CGI allows remote command execution |
---|
Risk Level: | High | Check or Attack Name: Handler Check |
---|---|---|
Platforms: | IRIX: 5.3, IRIX: 6.0.1, IRIX: 6.1, IRIX: 6.2, IRIX: 6.3, IRIX: 6.4, IRIX: 6.0, Common Gateway Interface (CGI) | |
Description: | The handler cgi-bin program contains a vulnerability that allows a remote attacker to execute arbitrary commands on a web server running a vulnerable version of the program. The handler program is part of the Outbox Environment Subsystem for IRIX, installed by default on all SGI systems running IRIX 6.2 or newer. Older versions of IRIX may have this package optionally installed. |
|
Remedy: | Disable the scripts included with the IRIX Outbox Environment Subsystem and obtain the patch(es) made available by SGI. To disable the scripts, follow these steps:
Patches: Patches are available from ftp://sgigate.sgi.com/Patches for the following versions: IRIX 5.3: #2315 available from ftp://sgigate.sgi.com/Patches/5.3/patch2315.tar. |
|
References: | Silicon Graphics Inc. Security Advisory 19970501-02-PX, IRIX webdist.cgi, handler and wrap programs, ftp://sgigate.sgi.com/security/19970501-02-PX |
Know Your Risks |