SCO OpenUnix and UnixWare contain a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when SCO Xserver (Xsco) fails to properly drop privileges when invoking external commands. This flaw may lead to a loss of integrity.
Classification
Location:
Local Access Required
Attack Type:
Input Manipulation,
Other
Impact:
Loss of Integrity
Exploit:
Exploit Available
Disclosure:
OSVDB Verified
Solution
Apply SCO hotfixes described in security advisory CSSA-2002-SCO.38 , as it has been reported to fix this vulnerability. An upgrade is required as there are no known workarounds.