Executive brief
A vulnerability in the password management utility of SCO UNIX 4.0 and earlier allows attackers to disrupt system access. By exploiting this flaw, an attacker can prevent legitimate users from logging into the system, effectively causing a denial of service. This could lead to significant operational downtime and prevent administrators from performing essential maintenance or security tasks.
Technical details
The vulnerability exists within the 'passwd' command of SCO UNIX versions 4.0 and earlier. While specific technical root causes like buffer overflows were not explicitly detailed in the legacy advisory, the flaw allows an attacker to manipulate the password system in a way that locks out users. The attack vector is listed as network-reachable with low complexity and no authentication required. Successful exploitation results in a denial of service (DoS) affecting system availability and integrity. Patches were historically addressed in CERT advisory CA-1993-08.
Affected products
- SCO UNIX 4.0 and earlier
Timeline
- 1993-05-24: advisory: NVD published date
- 1993-12-31: advisory: CERT advisory CA-1993-08 published