Junglewise Threat Intelligence

CVE-1999-1138: SCO UNIX insecure home directory permissions for system accounts

CVE-1999-1138 · Severity: critical · CVSS 10 · Published 1993-09-17

Vendors: Sco.

Executive brief

A security flaw in SCO UNIX operating systems allows unauthorized users to take control of specific system accounts. This occurs because certain system accounts were configured to use public temporary folders as their home directories. An attacker with access to the system could use this to gain elevated privileges, potentially leading to a full system compromise.

Technical details

The vulnerability arises from an insecure default configuration where the 'dos' and 'asg' system accounts are assigned world-writable home directories (/tmp and /usr/tmp, respectively). Because any user on the system can write to these directories, an attacker can place malicious initialization files (such as .profile or .login) or manipulate environment settings to execute arbitrary code when these accounts are accessed. This is a local privilege escalation vector that can lead to full administrative control if these accounts have high-level permissions or if further lateral movement is possible. The issue was originally identified in SCO UNIX System V/386 Release 3.2 and SCO Open Desktop.

Affected products

  • SCO UNIX System V/386 3.2
  • SCO Open Desktop All versions

Timeline

  • 1993-09-17: disclosed
  • 1993-09-17: advisory: NVD publication date

References

Related threats