{"id":"CVE-1999-1384","title":"Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the Remove…","summary":"Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the Remove…","severity":"high","cvss":7.2,"cvssVector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","published":"1996-10-30","updated":"2026-06-16","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-1999-1384","references":[{"url":"ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul","label":"cve@mitre.org"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I","label":"cve@mitre.org"},{"url":"http://marc.info/?l=bugtraq&m=87602167420095&w=2","label":"cve@mitre.org"},{"url":"http://www.iss.net/security_center/static/7456.php","label":"cve@mitre.org"},{"url":"http://www.securityfocus.com/bid/470","label":"cve@mitre.org"},{"url":"ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-96.08.SGI.systour.vul","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"ftp://patches.sgi.com/support/free/security/advisories/19961101-01-I","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://marc.info/?l=bugtraq&m=87602167420095&w=2","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.iss.net/security_center/static/7456.php","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://www.securityfocus.com/bid/470","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.01606,"epssPercentile":0.744,"ingestedAt":"2026-06-22T15:59:08.120Z","exploitAvailable":true,"exploits":{"exploitdb":true,"checkedAt":"2026-09-21T15:23:31.341Z"},"slug":"CVE-1999-1384","body":"## Overview\n\nIndigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain root privileges via a Trojan horse .exitops program, which is called by the inst command that is executed by the RemoveSystemTour program.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":52,"depthScoreParts":{"impact":39.6,"likelihood":0.3,"exploitation":12,"ransomware":0},"changes":[]}