SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#972598

SCO OpenServer vulnerable to privilege escalation in 'scosession' argument handling

Overview

A vulnerability in a program supplied with the SCO OpenServer operating system may allow local attackers to gain elevated privileges.

I. Description

SCO OpenServer is a UNIX-like operating system for Intel and AMD platforms. The 'scosession' session handling component, which is responsible for starting and stopping X server sessions, contains a flaw in the handling of command-line arguments which may allow a local authenticated attacker to gain elevated privileges. This applies to SCO OpenServer 5.0.6 and 5.0.7.

II. Impact

Local authenticated users may gain elevated privileges on affected platforms.

III. Solution

Apply an update

Updates for SCO OpenServer 5.0.6 and 5.0.7 are available at this time. More information can be found in SCO Security Advisory SCOSA-2005.5.

Systems Affected

VendorStatusDate NotifiedDate Updated
SCOVulnerable28-Jan-2005

References


ftp://ftp.sco.com/pub/updates/OpenServer/SCOSA-2005.5/SCOSA-2005.5.txt
http://secunia.com/advisories/14012/

Credit

Thanks to SCO Security for reporting this vulnerability, who in turn credit Joel Soderberg and Christer Oberg of Deprotect with the discovery.

This document was written by Ken MacInnis.

Other Information

Date Public:2005-01-25
Date First Published:2005-02-21
Date Last Updated:2005-02-21
CERT Advisory: 
CVE-ID(s):CAN-2003-1021
NVD-ID(s):CAN-2003-1021
US-CERT Technical Alerts: 
Metric:7.29
Document Revision:12

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader