sgi-midikeys-rogue-keyboard

HIGH (10.0) No Patch (9709 days)

Threat Intelligence

⚠️ CRITICAL GAP - Exploits exist but no detection available
EPSS Score: 2.08% chance of exploitation (percentile: 84%)
🔍 Detection Tools: None available in major open-source tools
⚔️ Exploit Availability: Exploit-DB

How we test →

What is it?

The sgi-midikeys program is a utility for editing MIDI files on SGI IRIX systems. It allows users to modify arbitrary files via a text editor, making it vulnerable to local file inclusion attacks.

Am I affected?

You're affected if you use the original sgi-midikeys version 1.0 or later. This is an older system software, so if you don't recognise the name, you're probably not affected. Check with your IT department if your organisation uses SGI IRIX systems.

Version info: Not specified in the advisory.
Check command: No specific check command provided; manual verification required.

Affected Products

Silicon Graphics Inc. / sgi-midikeys

How to fix

  1. Download the patched version from patches.sgi.com: ftp://patches.sgi.com/support/free/security/advisories/19990501-01-A
  2. Apply the patch manually to the sgi-midikeys program.
  3. Immediate mitigations:
    • Restrict access to the sgi-midikeys program (e.g., set permissions to read-only).
    • Monitor system logs for suspicious activity.