PT-1999-1795 · Sco · Sco Openserver
Published
1999-11-04
·
Updated
2016-10-18
·
CVE-1999-1571
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
SCO OpenServer versions 5.0.0 through 5.0.5
Description:
A buffer overflow issue in the sar command may allow local users to gain root privileges by providing a long -f parameter.
Recommendations:
For SCO OpenServer versions 5.0.0 through 5.0.5, avoid using the -f parameter with long inputs in the sar command until a fix is available. As a temporary workaround, consider restricting access to the sar command to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sco Openserver