Junglewise Threat Intelligence

CVE-1999-1302: SCO UNIX privilege escalation in pt_chmod

CVE-1999-1302 · Severity: high · CVSS 7.2 · Published 1994-11-30

Technologies: Sco Unix. Vendors: Sco.

Executive brief

A security vulnerability exists in a core utility of the SCO UNIX operating system. This flaw allows a person who already has a standard user account on the system to bypass security controls and gain full administrative (root) access. This could lead to a complete compromise of the server, including the theft of sensitive data or the disruption of business operations.

Technical details

A vulnerability exists in the pt_chmod executable within SCO UNIX versions 4.2 and earlier. pt_chmod is a utility typically used to set the permissions of a pseudo-terminal slave device. While the specific root cause is not detailed in the advisory, the flaw is categorized as a local privilege escalation. An attacker with local shell access can exploit this vulnerability to bypass authorization checks and execute commands with root-level privileges. This is a legacy vulnerability originally disclosed in 1994.

Affected products

  • SCO UNIX 4.2 and earlier

Timeline

  • 1994-11-30: disclosed: Initial public disclosure
  • 1994-11-30: advisory: NVD publication date

References

Related threats