OSVDB ID: 84287

Title: SCO UnixWare termsetup Variable Local Privilege Escalation

Info

Disclosure

Jul 20, 2012

Discovery

Unknown

Dates

Exploit

Jul 20, 2012

Solution

Unknown

Description

SCO UnixWare contains a flaw that may allow an attacker to gain access to unauthorized privileges. The issue is triggered when an error occurs in the termsetup variable handling. This may allow a local attacker to gain escalated root privileges.

Classification

Location: Local Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Discontinued Product
Exploit: Exploit Public
Disclosure: Uncoordinated Disclosure

Solution

The vendor has discontinued this product and therefore has no patch or upgrade that mitigates this problem. It is recommended that an alternate software package be used in its place.

Products

The SCO Group

UnixWare

1.1.2

References

Credit

Unknown or Incomplete



Direct URL: http://osvdb.org/84287