PT-1999-1795 · Sco · Sco Openserver

Published

1999-11-04

·

Updated

2016-10-18

·

CVE-1999-1571

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: SCO OpenServer versions 5.0.0 through 5.0.5
Description: A buffer overflow issue in the sar command may allow local users to gain root privileges by providing a long -f parameter.
Recommendations: For SCO OpenServer versions 5.0.0 through 5.0.5, avoid using the -f parameter with long inputs in the sar command until a fix is available. As a temporary workaround, consider restricting access to the sar command to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-1999-1571

Affected Products

Sco Openserver