Executive brief
A security flaw in the Digital Ultrix operating system allows local users to bypass security restrictions. By exploiting an improperly installed system utility, a user with limited access can gain full administrative control over the system. This could lead to unauthorized access to sensitive data, system-wide outages, or complete compromise of the server.
Technical details
The chroot utility in Digital Ultrix versions 4.0 and 4.1 is improperly installed, leading to a privilege escalation vulnerability. While the specific mechanism (such as setuid bits or directory permissions) is not detailed in the legacy advisory, the flaw allows a local attacker to break out of restricted environments or manipulate the system to gain root access. This is a local attack requiring no special authentication beyond initial system access. The vulnerability was originally identified in 1991 and is addressed in subsequent vendor patches or version upgrades.
Affected products
- Digital Ultrix 4.0, 4.1
Timeline
- 1991-05-01: disclosed: Initial disclosure of the vulnerability
- 1991-05-01: advisory: CERT advisory CA-1991-05 released