File: 1196.txt

package info (click to toggle)
snort 2.7.0-20.4
  • links: PTS
  • area: main
  • in suites: lenny
  • size: 34,512 kB
  • ctags: 18,772
  • sloc: ansic: 115,404; sh: 10,893; makefile: 1,372; perl: 487; sql: 213
file content (70 lines) | stat: -rw-r--r-- 1,565 bytes parent folder | download | duplicates (6)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
Rule:  

--

Sid:
1196

--

Summary:
This event is generated when an attempt is made to exploit a known
vulnerability in the IRIX infosrch.cgi web application.

--
Impact:
Execution of code of the attackers choosing is possible.

--
Detailed Information:
sgi IRIX 6.5 through 6.5.7 ships with a web application called InfoSearch
that is vulnerable to a remote execution attack.

An attacker may have abused the infosrch.cgi web application that ships
with IRIX 6.5 to remotely execute arbitrary commands as the webserver user.

--
Affected Systems:
	SGI IRIX 6.5 to 6.5.7
 
--
Attack Scenarios:
An attacker uses an existing, publically known exploit script, or
sends a simple, handcrafted URL to the webserver such as:
http://target/cgi-bin/infosrch.cgi?cmd=getdoc&db=man&fname=|/bin/id

--
Ease of Attack:
Simple. Exploits exist.

--
False Positives:
The InfoSearch web application may legitimately be used to browse system
documentation.

--
False Negatives:
None Known

--
Corrective Action:
Examine the packet to determine whether malicious code was contained in
the fname HTTP GET variable, such as unix shell commands.  If it looks
like it may have been malicious code, determine whether the targetted
web server was running a vulnerable version of IRIX.

Upgrade to the latest non-affected version of the product.

Apply the appropriate vendor supplied patches.

--
Contributors:
Original rule writer unknown
Original document author unkown
Sourcefire Vulnerability Research Team
Nigel Houghton <nigel.houghton@sourcefire.com>

--
Additional References:

--