COMMAND
On-Line Customer Registration
SYSTEMS AFFECTED
IRIX 6.2, 6.3, 6.4
PROBLEM
Following is based on Silicon Graphics Inc. Security Advisory.
The IRIX On-Line Customer Registration software is used to
establish an information link with Silicon Graphics and submit
your End User Registration form electronically. Unfortunately,
several vulnerabilities were discovered in On-Line Customer
Registration software subsystem which can lead to a root
compromise on a local machine. The On-Line Customer Registration
software is installed by default on IRIX 6.2 through IRIX 6.5
systems. On IRIX 6.2, the On-Line Customer Registration software
is part of the whatsnew software subsystem which is installed by
default. On IRIX 6.3 through 6.4, the On-Line Customer
Registration software is part of the Register(1) software
subsystem which is installed by default.
Even if the On-Line Customer Registration software has never been
used or configured, the software is installed by default and the
following information is applicable.
SOLUTION
For those customers that do not use the On-Line Customer
Registration software, the software should be removed. For those
customers that use the On-Line Customer Registration software, the
only complete solution is to upgrade the software.
OS Version Patch #
---------- -------
IRIX 6.2 Register 1.5
IRIX 6.3 Register 1.5.1
IRIX 6.4 Register 1.5.2