PT-2002-1088 · Sco · Openserver
Published
2002-05-01
·
Updated
2016-10-18
·
CVE-1999-1570
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
OpenServer version 5.0.5
Description
A buffer overflow issue in the sar command allows local users to gain root privileges by providing a long -o parameter.
Recommendations
For OpenServer version 5.0.5, avoid using the sar command with long -o parameters until a fix is available. As a temporary workaround, consider restricting access to the sar command to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Openserver