HTTP_Pfdisplay Execute

 

Code: p105

Severity: Notice

 

Description: The IRIS Performer API Search Tool is a Web-based search tool that assists in the searching of man pages, documents, example code, and special items known as classes, methods, tokens, and samples. The program pfdispaly.cgi contains a vulnerability that allows remote users to run any file on the system with 'nobody' privileges.

Impact: IRIX 6.2, 6.3, 6.4

Corrective: Users of SGI's IRIX 6.2, 6.3, or 6.4 systems should obtain and install patch 3018 as soon as possible.