Junglewise Threat Intelligence

CVE-1999-1304: SCO UNIX privilege escalation in login

CVE-1999-1304 · Severity: high · CVSS 7.2 · Published 1994-11-30

Technologies: Sco Unix. Vendors: Sco.

Executive brief

A security flaw in the login component of SCO UNIX allows individuals with physical or local access to the system to bypass security controls. By exploiting this vulnerability, a standard user can gain full administrative (root) privileges. This could lead to a total compromise of the server, including the theft of sensitive data and the ability to disrupt business operations.

Technical details

A privilege escalation vulnerability exists in the login utility of SCO UNIX versions 4.2 and earlier. The flaw allows a local, unauthenticated user to execute commands or manipulate the login process to obtain a root shell. While the specific technical root cause (such as a buffer overflow or environment variable manipulation) is not detailed in the legacy advisory, the impact is a complete loss of confidentiality, integrity, and availability. Attackers must have local access to the system to exploit this vulnerability. Users are advised to upgrade to a supported version or apply vendor-provided patches from the mid-1990s.

Affected products

  • SCO UNIX 4.2 and earlier

Timeline

  • 1994-11-30: disclosed

References

Related threats