PT-1998-1135 · Sco · Sco Openserver+1

Published

1998-08-27

·

Updated

2016-10-18

·

CVE-1999-1041

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SCO OpenServer version 5.0 SCO UNIX version 3.2v4
Description A buffer overflow issue in the mscreen component allows a local user to gain root access. This can be achieved through a long TERM environmental variable or a long entry in the .mscreenrc file.
Recommendations For SCO OpenServer version 5.0, restrict access to the mscreen component to minimize the risk of exploitation. For SCO UNIX version 3.2v4, avoid using long entries in the .mscreenrc file and long TERM environmental variables until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1041

Affected Products

Sco Openserver
Sco Unix