Junglewise Threat Intelligence

CVE-1999-1162: SCO UNIX passwd denial of service

CVE-1999-1162 · Severity: medium · CVSS 6.4 · Published 1993-05-24

Technologies: Sco Unix. Vendors: Sco.

Executive brief

A vulnerability in the password management utility of SCO UNIX 4.0 and earlier allows attackers to disrupt system access. By exploiting this flaw, an attacker can prevent legitimate users from logging into the system, effectively causing a denial of service. This could lead to significant operational downtime and prevent administrators from performing essential maintenance or security tasks.

Technical details

The vulnerability exists within the 'passwd' command of SCO UNIX versions 4.0 and earlier. While specific technical root causes like buffer overflows were not explicitly detailed in the legacy advisory, the flaw allows an attacker to manipulate the password system in a way that locks out users. The attack vector is listed as network-reachable with low complexity and no authentication required. Successful exploitation results in a denial of service (DoS) affecting system availability and integrity. Patches were historically addressed in CERT advisory CA-1993-08.

Affected products

  • SCO UNIX 4.0 and earlier

Timeline

  • 1993-05-24: advisory: NVD published date
  • 1993-12-31: advisory: CERT advisory CA-1993-08 published

References

Related threats