PT-2001-1776 · Sco · Sco Openserver

Published

2001-07-27

·

Updated

2017-12-19

·

CVE-2001-0578

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: SCO OpenServer versions 5.0 through 5.0.6
Description: A buffer overflow issue exists in the lpforms command of SCO OpenServer, which can be exploited by a local attacker to gain additional privileges. This is achieved by providing a long first argument to the lpforms command.
Recommendations: For SCO OpenServer versions 5.0 through 5.0.6, consider restricting access to the lpforms command until a patch is available. As a temporary workaround, avoid using long arguments with the lpforms command to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0578

Affected Products

Sco Openserver