PT-1998-1135 · Sco · Sco Openserver+1
Published
1998-08-27
·
Updated
2016-10-18
·
CVE-1999-1041
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SCO OpenServer version 5.0
SCO UNIX version 3.2v4
Description
A buffer overflow issue in the mscreen component allows a local user to gain root access. This can be achieved through a long TERM environmental variable or a long entry in the .mscreenrc file.
Recommendations
For SCO OpenServer version 5.0, restrict access to the mscreen component to minimize the risk of exploitation.
For SCO UNIX version 3.2v4, avoid using long entries in the .mscreenrc file and long TERM environmental variables until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sco Openserver
Sco Unix