Executive brief
A security flaw in the login component of SCO UNIX allows individuals with physical or local access to the system to bypass security controls. By exploiting this vulnerability, a standard user can gain full administrative (root) privileges. This could lead to a total compromise of the server, including the theft of sensitive data and the ability to disrupt business operations.
Technical details
A privilege escalation vulnerability exists in the login utility of SCO UNIX versions 4.2 and earlier. The flaw allows a local, unauthenticated user to execute commands or manipulate the login process to obtain a root shell. While the specific technical root cause (such as a buffer overflow or environment variable manipulation) is not detailed in the legacy advisory, the impact is a complete loss of confidentiality, integrity, and availability. Attackers must have local access to the system to exploit this vulnerability. Users are advised to upgrade to a supported version or apply vendor-provided patches from the mid-1990s.
Affected products
- SCO UNIX 4.2 and earlier
Timeline
- 1994-11-30: disclosed