PT-2001-2593 · Sco · Sco Openserver
Published
2001-12-31
·
Updated
2017-12-19
·
CVE-2001-1508
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SCO OpenServer versions 5.0 through 5.0.6a
Description
A buffer overflow issue exists in the lpstat command, allowing local users to execute arbitrary code as group bin by providing a long command line argument.
Recommendations
For SCO OpenServer versions 5.0 through 5.0.6a, consider restricting access to the lpstat command until a fix is available. As a temporary workaround, avoid using long command line arguments with the lpstat command to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sco Openserver