Junglewise Threat Intelligence

CVE-1999-1303: SCO UNIX privilege escalation in prwarn

CVE-1999-1303 · Severity: high · CVSS 7.2 · Published 1994-11-30

Technologies: Sco Unix. Vendors: Sco.

Executive brief

A vulnerability in the 'prwarn' utility of SCO UNIX allows a local user to gain full administrative control over the system. This utility is responsible for managing password expiration warnings. An attacker with basic access to the computer could exploit this flaw to bypass security restrictions, potentially leading to the theft of sensitive data or a complete system takeover.

Technical details

A privilege escalation vulnerability exists in the 'prwarn' utility within SCO UNIX versions 4.2 and earlier. The flaw allows a local, unprivileged user to execute arbitrary code or manipulate system processes to gain root-level privileges. While the specific technical root cause (such as a buffer overflow or insecure environment handling) is not detailed in the legacy advisory, the impact is a complete compromise of system integrity, confidentiality, and availability. Attackers must have local shell access to the system to execute the exploit.

Affected products

  • SCO UNIX 4.2 and earlier

Timeline

  • 1994-11-30: disclosed: Initial NVD publication date

References

Related threats