Executive brief
A security vulnerability exists in a core utility of the SCO UNIX operating system. This flaw allows a person who already has a standard user account on the system to bypass security controls and gain full administrative (root) access. This could lead to a complete compromise of the server, including the theft of sensitive data or the disruption of business operations.
Technical details
A vulnerability exists in the pt_chmod executable within SCO UNIX versions 4.2 and earlier. pt_chmod is a utility typically used to set the permissions of a pseudo-terminal slave device. While the specific root cause is not detailed in the advisory, the flaw is categorized as a local privilege escalation. An attacker with local shell access can exploit this vulnerability to bypass authorization checks and execute commands with root-level privileges. This is a legacy vulnerability originally disclosed in 1994.
Affected products
- SCO UNIX 4.2 and earlier
Timeline
- 1994-11-30: disclosed: Initial public disclosure
- 1994-11-30: advisory: NVD publication date