Executive brief
A vulnerability in the SCO UnixWare operating system allows local users to bypass security restrictions. By exploiting a flaw in a specific system call, an attacker with basic access to the system can read or modify any file and gain full administrative (root) control. This could lead to a complete compromise of the server and any data stored on it.
Technical details
A vulnerability exists in a specific system call within the SCO UnixWare kernel (versions 2.0.x and 2.1.0). The flaw allows a local, unprivileged user to bypass standard file system permissions. By successfully exploiting this system call, an attacker can read or write to arbitrary files on the system, leading to a full privilege escalation to root. The attack requires local access to the system but no special privileges. Patch information was historically available via SCO security bulletins (SB.96:02a).
Affected products
- SCO UnixWare 2.0.x, 2.1.0
Timeline
- 1996-09-04: disclosed: Initial publication date
- 1996-09-04: advisory: NVD publication date